Splunk Enterprise

indexer not working after changing cluster configuration

_pravin
Contributor

Hi,

I am trying to change the indexer configuration from one cluster master to another but in the process of this change the indexer never starts.

The web service log looks like below 

 

 

 

bash$ tail -f var/log/splunk/web_service.log
2024-11-01 16:26:18,141 INFO    [6724f3196d7f1cd30e7350] _cplogging:216 - [01/Nov/2024:16:26:18] ENGINE Bus EXITED
2024-11-01 16:26:18,141 INFO    [6724f3196d7f1cd30e7350] root:168 - ENGINE: Bus EXITED
2024-11-01 16:38:48,635 INFO    [6724f608607f04aeca7810] __init__:174 - Using default logging config file: /data/apps/SPLUNK_INDEXER_1/splunk/etc/log.cfg
2024-11-01 16:38:48,636 INFO    [6724f608607f04aeca7810] __init__:212 - Setting logger=splunk level=INFO
2024-11-01 16:38:48,636 INFO    [6724f608607f04aeca7810] __init__:212 - Setting logger=splunk.appserver level=INFO
2024-11-01 16:38:48,636 INFO    [6724f608607f04aeca7810] __init__:212 - Setting logger=splunk.appserver.controllers level=INFO
2024-11-01 16:38:48,636 INFO    [6724f608607f04aeca7810] __init__:212 - Setting logger=splunk.appserver.controllers.proxy level=INFO
2024-11-01 16:38:48,636 INFO    [6724f608607f04aeca7810] __init__:212 - Setting logger=splunk.appserver.lib level=WARN
2024-11-01 16:38:48,636 INFO    [6724f608607f04aeca7810] __init__:212 - Setting logger=splunk.pdfgen level=INFO
2024-11-01 16:38:48,636 INFO    [6724f608607f04aeca7810] __init__:212 - Setting logger=splunk.archiver_restoration level=INFO

 

 

 

Now I have even removed the clustering configuration from the server.conf but still the same issue with the Splunk instance.

Any one else face the same issue?

 

Regards,
Pravin

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Web service should be disabled on indexers so it's not unusual.

Check splunkd.log.

0 Karma

_pravin
Contributor

Hi @PickleRick ,

 

Thanks for the response. I agree that usually web service would be disabled but we keep the UI so that we can see the changes.

I managed to clean the indexer completely of all the configurations. Then recreate from backup and it worked.

 

Thanks,

Pravin

0 Karma
Get Updates on the Splunk Community!

Index This | What’s a riddle wrapped in an enigma?

September 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...