Splunk Enterprise

Taking off a peer which is already down from single site cluster



A peer was down recently because of some server issues and the buckets re balanced among themselves with the other servers.
I want to remove the peer from the indexer cluster as the the host cannot be used anymore.

And, Splunk is not running and cannot be run as one of the drives that hold the hot data got erased. There was no loss in the cluster as we are using the replication and search factors.

Could you please suggest a method or all the steps needed to remove the peer from a cluster safely.


0 Karma

Ultra Champion

hello there,

many answers here in the portal, example:

read here in docs:
read all the way through.

if the indexer is already down, run this command:
splunk offline --enforce-counts

hope it helps

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...