Does anybody know what parameters I should pass to the REST API endpoint /services/cluster/slave/control/control/decommission to archive the same thing that command 'splunk offline --enforce-counts' does?
Thanks!
Greeting from the future,
according to the latest docs https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTcluster#cluster.2Fslave.2Fcontrol.2F... it is like this :
curl -k -u admin:pass https://indexer:8089/services/cluster/slave/control/control/decommission -X POST
cheers, MuS
Through some testing, it seems that enforce_counts=true
might be the correct POST parameter.
It would be nice if someone from Splunk could confirm.
I've tested and confirmed that when you add the enforce_counts=true to the api call like seen below, it will perform a full decommissioning of the host. Thank you for bringing it up!
curl -k -u admin:pass https://indexer:8089/services/cluster/slave/control/control/decommission -d enforce_counts=true -X POST
Bumping this because I'd really like to know the answer.