Splunk Enterprise

Upgrading hardware on Indexers in cluster (one peer at a time)

braxton839
Explorer

I think I know how to do this but I thought it would be best to check with some of the experts here first.

 

I am upgrading the hardware (storage expansion) on our indexers and this will require turning off and unplugging each device. Indexers are clustered with a Replication Factor of 2.

From what I have read:

  • I can issue the 'splunk offline' command on the indexer I am working on
  • Wait for the indexer to wrap up any tasks
  • Then shut down and unplug the machine to perform this upgrade
  • Once complete, I can plug it back in and turn it back on (make sure Splunk starts running again)


Am i missing anything important?

Thanks!

Labels (1)
Tags (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @braxton839 

This looks good to me - Check the cluster manager first to ensure that things are in a good shape before offline-ing your indexer.

Be aware that with a RF of 2 you can only safely take down a single indexer at a time, and whilst it is down you are at risk of reduced data availability if your other indexers run into any problems.

Theres some good reading at https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/9.3/man... if it helps, but you may have already seen this.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

braxton839
Explorer

Thanks!

Which user should I be logged in as to run 'splunk offline', root or splunk?

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @braxton839 

This looks good to me - Check the cluster manager first to ensure that things are in a good shape before offline-ing your indexer.

Be aware that with a RF of 2 you can only safely take down a single indexer at a time, and whilst it is down you are at risk of reduced data availability if your other indexers run into any problems.

Theres some good reading at https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/9.3/man... if it helps, but you may have already seen this.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...