Getting Data In

What is the difference between maintenance mode versus off-line during a Linux patch?

ddrillic
Ultra Champion

We have a Linux patch which requires a server reboot scheduled tonight for one out of the ten indexers. The patch would be applied at night at some point.

We wonder whether we should put the entire cluster on maintenance mode or maybe take this specific indexer off-line for the whole night.

0 Karma

ddrillic
Ultra Champion
0 Karma

ddrillic
Ultra Champion

Our sales engineer said -

  • Well don't put the entire cluster in maintenance mode, that would cause an enormous amount of load when you brought it out of maintenance mode, and makes your new data since the maintenance mode went into effect very unsafe.

No, offline that server nicely and add it back at your leisure.

0 Karma

tiagofbmm
Influencer

Well as the docs say,

Maintenance mode halts most bucket fixup activity and prevents frequent rolling of hot buckets.

https://docs.splunk.com/Documentation/Splunk/7.0.2/Indexer/Usemaintenancemode

What will happen when you put that peer offline is that all the hot buckets will be rolled to warm as a result of the splunk stop command.

If you do this very often, you may end up having very small buckets in your environment, which is not great as Splunk would need to check several buckets for the data someone has searched instead of few.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...