Getting Data In

What is the REST API endpoint used to remove an index peer from an index cluster?

brent_weaver
Builder

Hello all.
I am scaling back our index tier through automation and I have been unable to find out how to remove a peer from the index cluster via REST API. I know that I need the GUID of the peer I want to remove, that's easy, I just want to be able to do all this work from "afar" and not have to log in to each instance to do this.

So the question is, what is the REST API endpoint I would use to remove an index peer from an index cluster?

Thanks in advance.

0 Karma

arjunpkishore5
Motivator

You can use cluster/master/peers to get all peers in your cluster. The title field gives you the guid (The title field is not listed in the return values. However, it is returned. Look at the sample response XML) . and then you can use cluster/master/control/control/remove_peers to use the guid to remove the peer.

Docs: https://docs.splunk.com/Documentation/Splunk/8.0.0/RESTREF/RESTcluster

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...