Monitoring Splunk

Splunk shc member abnormal

meng
New Member
I use metadata to monitor the activity status of member nodes in my cluster, but recently I discovered an exception. My SHC member 01 was found to be inactive, and the last time metadata was sent was a long time ago. However, when I checked my SHC cluster member status in the background, it was always in the up state, and the last time it was sent to the administrator was also recently. I restarted my member 1, but it seems that the latest time of member 1 cannot be seen in the metadata
0 Karma

tej57
Builder

Hey @meng,

You can also check the latest status of your search head cluster using REST endpoint as mentioned here - https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/9.4/cluster-endpo...

It'll always fetch the latest information for your cluster. And as for getting inaccurate information from metadata, as @gcusello mentioned, open up a support case with Splunk.

Thanks,
Tejas.  

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @meng ,

I never experienced this issue, opena a case to Splunk Support, for your case and also for the other Splunk Customer.

Ciao.

Giuseppe

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...