We have four indexers in a cluster, single site, with RF=3 and SF=2.
We will have a maintenance that will require two indexers power down (EC2 instances), and the maintenance will last about two hours.
What will be the proper way or sequence for taking those two indexer servers power down?
Should I do splunk offline on one indexer first, power down, wait for a while, and then proceed to other indexer?
or should I do splunk offline on both servers , and power down simultaneously?
splunk offline is not recommended for two hours long.
you can enable maintenance-mode on cluster master.
you can do below:
you can do same for other Indexer at the same time.
once you are done with activity on both servers. You can enable maintenance-mode on cluster master.