Splunk Enterprise

Solution to error: Cluster is not indexing ready, please bring up at least RF number of peers?

Mukunda7
Explorer

Hello,

After upgrading Splunk version from 8.1.5 to 9.0 we are getting indexing not ready error in Splunk deployment server.  Anything we need to perform in indexer clustering.

What is the solution? Can anyone help.

 

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are all of your indexers up?  Is the RF met?  If both are true then you can ignore the "error".

Why is the Deployment Server even reporting this?  Is it also your Monitoring Console?  If so, is the MC still configured properly?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Mukunda7
Explorer

@richgalloway 

Actually 2 indexers are not working form last 3 months. Now we have upgraded all other indexers and we have not seen this error before upgrade. Actually we have some another monitoring console in our distributed environment. 

So as part of upgradation we first performed this activity in dev environment and found this issue. Can you guide on this.

Whwn I checked MC everything is perfect serach factor and replication factoe met but this instance is showing unhealthy.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I would trust what the MC says about the environment's health over what the DS says.  Still, it's a good idea to get those 2 indexers working again.

Consider disabling the check on the DS.  Click on the Health icon then click the Health Report Manager link.  Scroll down to "feature:indexing_ready" and click on it.  Turn off both switches then click Save.

---
If this reply helps you, Karma would be appreciated.

Mukunda7
Explorer

We didn't found that feature "feature:indexing_ready" in our DS.

 

What can be done, still health is red?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Which version of Splunk is the DS using?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...