Splunk Search

How to push out an indexer bundle after rebuilding a server?

a212830
Champion

Hi,

I had to rebuild an indexer, and it's now up and running, but it doesn't have the most recent updates that we have done from the cluster master, as the server was down when these were pushed out. Can I just do a push from the cluster master, or do I need to create a dummy change to force the cluster master to recognize that something has changed?

0 Karma
1 Solution

prakash007
Builder

You can run cluster-bundle-status from cluster master to check if the new indexer added has the active_bundle/latest checksum, if not you can apply a cluster-bundle(I hope that should work)

View solution in original post

dkeck
Influencer

Hi,

if the server was readded to the cluster it should have gotten the bundle. If not, as far as I know, you need a change to push a new one.

0 Karma

prakash007
Builder

You can run cluster-bundle-status from cluster master to check if the new indexer added has the active_bundle/latest checksum, if not you can apply a cluster-bundle(I hope that should work)

a212830
Champion

Thanks. I ran the command, and it appears that the cluster master thinks that the bundle is there, but they aren't. I'm looking at that directory, and the updated files are missing. Can I just do a push again, or do I need to make an actual change?

0 Karma

a212830
Champion

Never mind. All set. My bad.

0 Karma

prakash007
Builder

@a212830 : accept an answer for future readers.

0 Karma

prakash007
Builder

so, you don't see a latest bundle when you did apply bundle-push from cluster-master..??
If not, you might have to make a dummy change to get a new checksum or do a rolling restart form cluster-master if that helps.

0 Karma

dkeck
Influencer

you can try but it should tell you that all peers have the newest bundle

0 Karma
Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...