Hi, Splunk Folks, I would like to why INDEXER crashes very often in the Cluster Environment. What are the steps I need to check. Any config needs to be checked? tuned?. I am new to Splunk Admin.
if you have a crash in a production system, open immediately a case to Splunk support, sending them a diag of the crushed system.
If your system is blocked (or in your case indexer frequently crashes), they call in max 30 minuts.
Remember the diag!