Splunk Enterprise

Status of splunk offline

bsrikanthreddy5
Path Finder

Hi, 

I ran "splunk offline --enforce-counts" command on one of the indexer servers in a multisite cluster. it has been over a day. I would like to know the status or progress of my offline command.

Is there a way to know status or progress?

Labels (1)
Tags (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

I cannot test on my environment but I think you should be able to see on Cluster Master - Indexer clustering | Bucket Status fixing activities. Although it will not show you estimated recovery time, but you can monitor how many buckets are waiting for fix.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

scelikok
SplunkTrust
SplunkTrust

@bsrikanthreddy5, you can view the status on Cluster Master - Indexer clustering dashboard. The state should be shown as GracefulShutdown after the indexer decommissioned.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

bsrikanthreddy5
Path Finder

@scelikok I was looking to know the progress, I mean how many buckets or data size in GB or MB are still pending to replicate from the indexer where I ran splunk offline command

0 Karma

scelikok
SplunkTrust
SplunkTrust

I cannot test on my environment but I think you should be able to see on Cluster Master - Indexer clustering | Bucket Status fixing activities. Although it will not show you estimated recovery time, but you can monitor how many buckets are waiting for fix.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...