Installation

How can convert the replication factor raw log to searchable data in index cluster

msplunk33
Path Finder

How can convert the replication factor raw log to searchable data incase the searchable data is not available in a indexer. Is this a automated process by indexer or manual process.

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

this is automated process, which starts after CM has realized that one node is missing from cluster. Unfortunately I couldn’t found any good presentation of this. There are at least in some training materials where this was clearly presented.

r. Ismo

0 Karma

msplunk33
Path Finder

@isoutamo  Do you mean one node completely fail or just unresponsive. when CM start this process What is the  process of restoring a comply failed node after a failure. How about the previous log this node was storing will it be automatically restored if we rejoin this node as a new fresh node with same disc structure. Do we need to manually copy the old log.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Here is described what and how bucket fixing has done when peers go offline.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Indexer/Whathappenswhenaslavenodegoesdown

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...