- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Powering down Indexers for maintenance
We have four indexers in a cluster, single site, with RF=3 and SF=2.
We will have a maintenance that will require two indexers power down (EC2 instances), and the maintenance will last about two hours.
What will be the proper way or sequence for taking those two indexer servers power down?
Should I do splunk offline on one indexer first, power down, wait for a while, and then proceed to other indexer?
or should I do splunk offline on both servers , and power down simultaneously?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


splunk offline is not recommended for two hours long.
you can enable maintenance-mode on cluster master.
you can do below:
- stop the Splunk Indexer
- disable boot-start (if you need to do multiple restart during your maintenance, this will avoid starting of splunk service)
- once you are done with activity you can start splunk and enable boot-start.
you can do same for other Indexer at the same time.
once you are done with activity on both servers. You can enable maintenance-mode on cluster master.
If this helps, give a like below.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


If they both have to be down at the same time, then IMO it's better bring them both down at about the same time. That will keep the CM from moving primary buckets to the indexer that's next to go down.
If this reply helps you, Karma would be appreciated.
