Hi Team, I need to decrease the number of indexers used to half, in my current configurations we have site replication factor is 5 in total with origin:3 and site searchfactor is defined as 3 in tot...
...ardware Implementing new indexes.conf to take advantage of volumes and to address changes in partitions Some misc notes: The indexers on on Linux and moving to a server with Linux Version is staying t...
...earches running on the detention server after 1 hour. We have the following set in the server.conf:
decommission_force_finish_idle_time = 0
decommission_node_force_timeout = 300
d...
So looking at the docs moving the index buckets is generally how you move data. However, I'm migrating a lot of data from multiple servers to one server and apparently moving the index buckets will b...
Hi, In our Splunk Architecture Indexers were setup in 2015 and now we need to put manual detention on one of the indexers but I am not able to do this as I don't know the admin password. Can s...
...uild new Deployer ( new IP, new FQDN), install Splunk... 2) configure with the [shclustering] stanza in /opt/splunk/etc/system/local server.conf [shclustering] pass4SymmKey =<secret&g...
Hi,
We had put one of our Peers/Indexers (Lets name it IDX2) into manual detention using the command below:
Run in IDX2
/opt/splunk/bin/splunk edit cluster-config -manual_detention on
A...
Hi,
I have a legacy Splunk Enterprise cluster that consists of:
1 cluster master
3 indexers, forming an indexer cluster
1 search head
1 license master
This cluster will stop receiving...