In my organization Patching activity has been scheduled and under that all my splunk components will be down i.e Search head,Indexers,Master server etc.
I need to bring all the Splunk components down and then restart them after 9 hours of maintenance.
Can anyone tell me any standard procedure to do this activity. Like which component should be down and bring up first.
I will really appreciate help on this.