Knowledge Management

Relocate KVstore in a cluster

nawazns5038
Builder

Hi,

How do we relocate the KVstore on to a new location in a search head cluster.

I heard that there are some settings on the server.conf which would help in relocating the KVstore but what is the safest way to do it in a cluster without causing any KV store errors ??

Thanks

0 Karma

dchoi_splunk
Splunk Employee
Splunk Employee

Tested on SHC which has 3 members:
To change the default kvstore path to a different mount point in SHC, below steps can be doable.

  1. Stop the service on one of search head member(not kvstore primary)
  2. Repoint the kvstore path to a newly created empty directory with write permission (http://docs.splunk.com/Documentation/Splunk/latest/Admin/Serverconf?utm_source=answers&utm_medium=in...)
  3. Start the service
  4. Check if resync is working.
  5. then repeat 1-4 for the next member

Above steps worked.

0 Karma

solarboyz1
Builder

You will need to do it one member at a time.

Take the member out of the cluster.
shut member down
Follow instructions to move kvstore
Start member
Add member to cluster

Repeat on next cluster member.

0 Karma

solarboyz1
Builder

I don't believe so, the cluster will not recognize changes made by edits to the ../etc/system/local/server.conf.

If you're concerned...then you could shut the entire cluster down and move the location. Just requires and outage.

0 Karma

nawazns5038
Builder

If we do that won't there be any errors if the member joins back with a different KV store location than others ? ?

0 Karma

p_gurav
Champion
0 Karma

nawazns5038
Builder

yup, but how do you do it in a cluster without any errors ??

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...