Splunk Enterprise

Status of splunk offline

bsrikanthreddy5
Path Finder

Hi, 

I ran "splunk offline --enforce-counts" command on one of the indexer servers in a multisite cluster. it has been over a day. I would like to know the status or progress of my offline command.

Is there a way to know status or progress?

Labels (1)
Tags (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

I cannot test on my environment but I think you should be able to see on Cluster Master - Indexer clustering | Bucket Status fixing activities. Although it will not show you estimated recovery time, but you can monitor how many buckets are waiting for fix.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

scelikok
SplunkTrust
SplunkTrust

@bsrikanthreddy5, you can view the status on Cluster Master - Indexer clustering dashboard. The state should be shown as GracefulShutdown after the indexer decommissioned.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

bsrikanthreddy5
Path Finder

@scelikok I was looking to know the progress, I mean how many buckets or data size in GB or MB are still pending to replicate from the indexer where I ran splunk offline command

0 Karma

scelikok
SplunkTrust
SplunkTrust

I cannot test on my environment but I think you should be able to see on Cluster Master - Indexer clustering | Bucket Status fixing activities. Although it will not show you estimated recovery time, but you can monitor how many buckets are waiting for fix.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...