Installation

How to undo integration of SHC with multisite indexer cluster?

gkas99
Explorer

As part of deployment rollback, how do we undo integrating SHC with multisite indexer cluster done with following command from this instruction - https://docs.splunk.com/Documentation/Splunk/9.0.1/DistSearch/SHCandindexercluster#Configure_members ?

 

 

splunk edit cluster-config -mode searchhead -site site0 -manager_uri https://10.152.31.202:8089 -secret newsecret123 -auth login:password 

splunk restart

 

 

 

 

Labels (2)
0 Karma
1 Solution

chaker
Contributor

Hi @gkas99 

Do you want to revert to single site or distributed search?

All config for SHC is found under the [clustering] stanza in server.conf on each SH. You could open server.conf, remove the config for clustering and restart. This will give you a blank slate to configre the SH however you like.

If you want to go back to single site, the command above you provided will work, just remove the -site reference.

View solution in original post

chaker
Contributor

Hi @gkas99 

Do you want to revert to single site or distributed search?

All config for SHC is found under the [clustering] stanza in server.conf on each SH. You could open server.conf, remove the config for clustering and restart. This will give you a blank slate to configre the SH however you like.

If you want to go back to single site, the command above you provided will work, just remove the -site reference.

Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...