Knowledge Management

How can enable kvstore monitoring for seach head cluster members

mahboubi66
Engager

Hi

We have a search head cluster with three members, as you know all members have same "default host name".

When I try to enable KVStore monitoring in monitoring console it says "Duplicate instance name. Ensure each instance has a unique instance (host) name." But because they are member of search head cluster I can't assign unique name to each one.

How can I enable KVStore monitoring for search head cluster members?

Labels (1)
Tags (1)
0 Karma
1 Solution

ivanreis
Builder

Hi @mahboubi66 ,

In order to have the search head cluster working properly, you have to name each server with a unique name, you should not have duplicated name. Should be server1, server2 and server3 as a sample, after you rename the servers, please restart splunk service.
In the top of splunk search head cluster, a load balancer have to be setup with the 3 servers fqdn. The load balancer will forwarder the traffic to each server accordingly, so when the users type the url on the browser, the load balancer will know which servers to send the user request and allow users to connect and run their reports.

Check this link for SHCluster architecture : https://docs.splunk.com/Documentation/Splunk/8.1.0/DistSearch/SHCarchitecture

After you rename all those servers and restart splunk service, the kvstore should start properly. 

In order to troubleshoot the kvstore, please check this link here: https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/TroubleshootKVstore

I hope this can help you, if so, please accept the answer.

 

 

View solution in original post

0 Karma

ivanreis
Builder

Hi @mahboubi66 ,

In order to have the search head cluster working properly, you have to name each server with a unique name, you should not have duplicated name. Should be server1, server2 and server3 as a sample, after you rename the servers, please restart splunk service.
In the top of splunk search head cluster, a load balancer have to be setup with the 3 servers fqdn. The load balancer will forwarder the traffic to each server accordingly, so when the users type the url on the browser, the load balancer will know which servers to send the user request and allow users to connect and run their reports.

Check this link for SHCluster architecture : https://docs.splunk.com/Documentation/Splunk/8.1.0/DistSearch/SHCarchitecture

After you rename all those servers and restart splunk service, the kvstore should start properly. 

In order to troubleshoot the kvstore, please check this link here: https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/TroubleshootKVstore

I hope this can help you, if so, please accept the answer.

 

 

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...