Security

Quarantine a Peer before or after running splunk offline command

jordanking1992
Path Finder

Hello,

 

It seems that my current process of quarantining a search peer and then running 'splunk offline' causes searches to become zombified.

"This search has encountered a fatal error and has been marked as zombied."

 

Is it best practice to quarantine the peer before or after running the splunk offline command? I know that running 'splunk offline' graceful haults new searches from reaching that indexer but for some reason, I think there is an interference when quarantining the host first and then running 'splunk offline'.

 

Thoughts?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I've never seen anyone quarantine an indexer before stopping it as the offline command accomplishes the same thing.  Since using quarantine seems to cause problems for you, you should stop doing it.

---
If this reply helps you, Karma would be appreciated.

jordanking1992
Path Finder

Thanks richgalloway. My goal is upgrade the indexer cluster without the end user seeing warnings when a peer goes down for the upgrade. Since removing the quarantine task, things are a little better,however, I am still occasionally get the "connection refused for peer=x" when the peer goes down via 'splunk offline' and a search was ran at the same time.

Is it nearly impossible to perform an indexer cluster upgrade without a few "connection refused" warnings when a search is ran during a peer being down?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Many customers will perform upgrade during off-peak hours in part to reduce this problem.  I know of no way to avoid it completely.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...