Splunk Enterprise

Updating the indexer clustering master node but not able to update the peer node

All-done-steak
Loves-to-Learn Lots

I have increase the Max Size of the "main" index at indexer clustering master node. I tried to push it to the peer node, it showed successful and I have also restart the peer node (Server Control --> Restart Splunk). 

The Max Size of the "main" index is still not updated.

 

 

Splunk Enterprise version: 8.2

Labels (2)
0 Karma

kiran_panchavat
Motivator

@All-done-steak 

You need to create an `indexes.conf` file in either `/opt/splunk/etc/manager-apps` or `/opt/splunk/etc/master-apps`. Afterward, push the configuration, and it will appear on the indexers under `/opt/splunk/etc/peer-apps`.

I hope this helps, if any reply helps you, you could add your upvote/karma points to that reply, thanks.
0 Karma

kiran_panchavat
Motivator

@All-done-steak 

The main index serves as the default index. I recommend creating a new index and applying the desired settings. Then, navigate to the cluster master and push the changes using the following command:

/opt/splunk/bin/splunk apply cluster-bundle

Afterward, check the bundle status.

For an Indexer cluster, use the CLI on the Cluster Master to run:

/opt/splunk/bin/splunk show cluster-bundle-status

I hope this helps, if any reply helps you, you could add your upvote/karma points to that reply, thanks.
0 Karma

PaulPanther
Motivator

How to you verified that the parameter was not updated? Have you checked the changed indexes.conf on a peer node?

If not, please check it and execute $SPLUNK_HOME/bin/splunk btool indexes list main --debug to check the parameter and its app location.

It’s possible that another indexes.conf file takes precedence over your modified configuration.

0 Karma
Get Updates on the Splunk Community!

Digital Resilience Assessment Launch | How prepared are you for disruption?

Disruption is inevitable. The question is – how prepared are you to handle it? In today’s fast-moving digital ...

Buttercup Games: Further Dashboarding Techniques (Part 2)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Index This | What is the next number in the series? 7,645 5,764 4,576…

February 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...