Splunk Enterprise

How to take an Indexer (indexA.aws.gov) out of a Cluster during a maintenance to avoid data loss. Thanks a million

SamHTexas
Builder

I work in a large environment clustered mostly, have Splunk Ent., ES. SHs & Indexers clustered) There is a maintenance being done & we are told that the indexer will be moved to a new host & data loss will occur. How do I move this indexer out of of the cluster briefly to avoid data loss please? Thanks very  much for your help in advance.

Labels (2)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

it depends is this a temporary (and how long time) or permanent removal. Anyhow you can read and follow these instructions https://docs.splunk.com/Documentation/Splunk/8.2.3/Indexer/Takeapeeroffline to do this.

SamHTexas
Builder

Tanks for your message. It  is a perm. move. Is it correct that the data is lost on AWS as soon as the Indexer it stopped? Please advise best practices for temporary or a permanent move. In the current case is permanent. Thank u a million in advance for your time sir.

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

If/when you have an indexer and your SF/RF >= 2 then you don't lose data as you have at least one copy of every bucket. It could be short time when searches don't found all data (when bucket are rebuild for search), but you don't lose the data.

You should just follow the document's instructions how to remove peer permanently from cluster. Nothing rocket science, just step by step and reserve enough time for those bucket moves/repairs.

If your RF=1 then you must figure out what is the best way to replace current peer and change RF asap at least to 2.

r. Ismo

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...