Splunk Search

How to push out an indexer bundle after rebuilding a server?

a212830
Champion

Hi,

I had to rebuild an indexer, and it's now up and running, but it doesn't have the most recent updates that we have done from the cluster master, as the server was down when these were pushed out. Can I just do a push from the cluster master, or do I need to create a dummy change to force the cluster master to recognize that something has changed?

0 Karma
1 Solution

prakash007
Builder

You can run cluster-bundle-status from cluster master to check if the new indexer added has the active_bundle/latest checksum, if not you can apply a cluster-bundle(I hope that should work)

View solution in original post

dkeck
Influencer

Hi,

if the server was readded to the cluster it should have gotten the bundle. If not, as far as I know, you need a change to push a new one.

0 Karma

prakash007
Builder

You can run cluster-bundle-status from cluster master to check if the new indexer added has the active_bundle/latest checksum, if not you can apply a cluster-bundle(I hope that should work)

a212830
Champion

Thanks. I ran the command, and it appears that the cluster master thinks that the bundle is there, but they aren't. I'm looking at that directory, and the updated files are missing. Can I just do a push again, or do I need to make an actual change?

0 Karma

a212830
Champion

Never mind. All set. My bad.

0 Karma

prakash007
Builder

@a212830 : accept an answer for future readers.

0 Karma

prakash007
Builder

so, you don't see a latest bundle when you did apply bundle-push from cluster-master..??
If not, you might have to make a dummy change to get a new checksum or do a rolling restart form cluster-master if that helps.

0 Karma

dkeck
Influencer

you can try but it should tell you that all peers have the newest bundle

0 Karma
Get Updates on the Splunk Community!

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...