Knowledge Management

How can enable kvstore monitoring for seach head cluster members

mahboubi66
Engager

Hi

We have a search head cluster with three members, as you know all members have same "default host name".

When I try to enable KVStore monitoring in monitoring console it says "Duplicate instance name. Ensure each instance has a unique instance (host) name." But because they are member of search head cluster I can't assign unique name to each one.

How can I enable KVStore monitoring for search head cluster members?

Labels (1)
Tags (1)
0 Karma
1 Solution

ivanreis
Builder

Hi @mahboubi66 ,

In order to have the search head cluster working properly, you have to name each server with a unique name, you should not have duplicated name. Should be server1, server2 and server3 as a sample, after you rename the servers, please restart splunk service.
In the top of splunk search head cluster, a load balancer have to be setup with the 3 servers fqdn. The load balancer will forwarder the traffic to each server accordingly, so when the users type the url on the browser, the load balancer will know which servers to send the user request and allow users to connect and run their reports.

Check this link for SHCluster architecture : https://docs.splunk.com/Documentation/Splunk/8.1.0/DistSearch/SHCarchitecture

After you rename all those servers and restart splunk service, the kvstore should start properly. 

In order to troubleshoot the kvstore, please check this link here: https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/TroubleshootKVstore

I hope this can help you, if so, please accept the answer.

 

 

View solution in original post

0 Karma

ivanreis
Builder

Hi @mahboubi66 ,

In order to have the search head cluster working properly, you have to name each server with a unique name, you should not have duplicated name. Should be server1, server2 and server3 as a sample, after you rename the servers, please restart splunk service.
In the top of splunk search head cluster, a load balancer have to be setup with the 3 servers fqdn. The load balancer will forwarder the traffic to each server accordingly, so when the users type the url on the browser, the load balancer will know which servers to send the user request and allow users to connect and run their reports.

Check this link for SHCluster architecture : https://docs.splunk.com/Documentation/Splunk/8.1.0/DistSearch/SHCarchitecture

After you rename all those servers and restart splunk service, the kvstore should start properly. 

In order to troubleshoot the kvstore, please check this link here: https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/TroubleshootKVstore

I hope this can help you, if so, please accept the answer.

 

 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...