Splunk Enterprise

Upgrading hardware on Indexers in cluster (one peer at a time)

braxton839
Explorer

I think I know how to do this but I thought it would be best to check with some of the experts here first.

 

I am upgrading the hardware (storage expansion) on our indexers and this will require turning off and unplugging each device. Indexers are clustered with a Replication Factor of 2.

From what I have read:

  • I can issue the 'splunk offline' command on the indexer I am working on
  • Wait for the indexer to wrap up any tasks
  • Then shut down and unplug the machine to perform this upgrade
  • Once complete, I can plug it back in and turn it back on (make sure Splunk starts running again)


Am i missing anything important?

Thanks!

Labels (1)
Tags (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @braxton839 

This looks good to me - Check the cluster manager first to ensure that things are in a good shape before offline-ing your indexer.

Be aware that with a RF of 2 you can only safely take down a single indexer at a time, and whilst it is down you are at risk of reduced data availability if your other indexers run into any problems.

Theres some good reading at https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/9.3/man... if it helps, but you may have already seen this.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

braxton839
Explorer

Thanks!

Which user should I be logged in as to run 'splunk offline', root or splunk?

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @braxton839 

This looks good to me - Check the cluster manager first to ensure that things are in a good shape before offline-ing your indexer.

Be aware that with a RF of 2 you can only safely take down a single indexer at a time, and whilst it is down you are at risk of reduced data availability if your other indexers run into any problems.

Theres some good reading at https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/9.3/man... if it helps, but you may have already seen this.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...