Splunk Enterprise Security

Splunk Enterprise 7.1, ES 5.1 and phased_execution_mode

janispelss
Path Finder

I have been looking into upgrading our Splunk Enterprise deployment to version 7.1.1, which would also require upgrading Splunk ES to 5.1. I saw this under the compatibility table in the ES docs for the deployment planning:

Splunk Enterprise Security 5.1 is compatible with Splunk Enterprise v 7.1.x only by setting phased_execution_mode=singlethreaded in order to avoid an issue that will be fixed in an upcoming Splunk Enterprise release.

On which instances should this setting be configured? We have an indexer cluster and 2 search heads - one for ES and one for other uses.

How would adding this setting impact non-ES uses? There's not much information available about it, and what is the issue that adding the setting fixes.

And finally, maybe anyone knows in which Splunk version the fix could be available? Since we're not really in a hurry to make the upgrade, maybe it's better to just wait until the the issue is fixed?

danan5
Path Finder

Hi, I have been looking into this and as far as I can tell the line "phased_execution_mode=singlethreaded" needs to be added to [search] stanza in the limits.conf on the ES search head only.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...