Splunk SOAR

Is it impossible to use Phantom's ibackup on a warm standby server?

gf13579
Communicator

I've configured a pair of Phantom servers to use warm standby. As per the documentation, I ran ibackup.pyc --setup after setting up warm standby, then ibackup.pyc --backup and it works fine.

If I try to run the --backup command on the warm standby I get errors:

 

 

[23/Jul/2020 01:40:00] ERROR: ERROR [057]: : recovery is in progress
HINT: pg_walfile_name() cannot be executed during recovery.:

 

 

Presumably this is due to the way warm standby works, but the documentation is unclear.

Is this expected behaviour, and is the only option to accept that the standby server backups will fail until a failover occurs i.e. the standby becomes the primary?

Labels (3)
0 Karma

phanTom
SplunkTrust
SplunkTrust

@gf13579 I recently saw this at a customer and got the same thing. I guess it makes sense that as the DB is constantly being streamed to the STBY i makes sense that a backup might be hard/impossible. 
For the customer I implemented the same cron job on both servers and monitored the backup logs. We tested in a DR scenario and the backup was successfully created when the STBY was made PRI.

richgalloway
SplunkTrust
SplunkTrust
Whenever you find a Splunk document that is not clear, be sure to submit Feedback at the bottom of the page. Splunk is very good about updating docs in response to user feedback.
---
If this reply helps you, Karma would be appreciated.

gf13579
Communicator

I do this!

I got a mistake on this page (build_phantom_rest_url vs. _construct_rest_url) fixed by the technical writers earlier this week: https://docs.splunk.com/Documentation/Phantom/4.9/Playbook/VPECustomFunctionBlock.

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...