Knowledge Management

How can enable kvstore monitoring for seach head cluster members

mahboubi66
Engager

Hi

We have a search head cluster with three members, as you know all members have same "default host name".

When I try to enable KVStore monitoring in monitoring console it says "Duplicate instance name. Ensure each instance has a unique instance (host) name." But because they are member of search head cluster I can't assign unique name to each one.

How can I enable KVStore monitoring for search head cluster members?

Labels (1)
Tags (1)
0 Karma
1 Solution

ivanreis
Builder

Hi @mahboubi66 ,

In order to have the search head cluster working properly, you have to name each server with a unique name, you should not have duplicated name. Should be server1, server2 and server3 as a sample, after you rename the servers, please restart splunk service.
In the top of splunk search head cluster, a load balancer have to be setup with the 3 servers fqdn. The load balancer will forwarder the traffic to each server accordingly, so when the users type the url on the browser, the load balancer will know which servers to send the user request and allow users to connect and run their reports.

Check this link for SHCluster architecture : https://docs.splunk.com/Documentation/Splunk/8.1.0/DistSearch/SHCarchitecture

After you rename all those servers and restart splunk service, the kvstore should start properly. 

In order to troubleshoot the kvstore, please check this link here: https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/TroubleshootKVstore

I hope this can help you, if so, please accept the answer.

 

 

View solution in original post

0 Karma

ivanreis
Builder

Hi @mahboubi66 ,

In order to have the search head cluster working properly, you have to name each server with a unique name, you should not have duplicated name. Should be server1, server2 and server3 as a sample, after you rename the servers, please restart splunk service.
In the top of splunk search head cluster, a load balancer have to be setup with the 3 servers fqdn. The load balancer will forwarder the traffic to each server accordingly, so when the users type the url on the browser, the load balancer will know which servers to send the user request and allow users to connect and run their reports.

Check this link for SHCluster architecture : https://docs.splunk.com/Documentation/Splunk/8.1.0/DistSearch/SHCarchitecture

After you rename all those servers and restart splunk service, the kvstore should start properly. 

In order to troubleshoot the kvstore, please check this link here: https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/TroubleshootKVstore

I hope this can help you, if so, please accept the answer.

 

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...