We have an indexer which is going to be down for several days, so in preparation for that I performed these steps:
splunk offline on site1 indexer
Changed server.conf on the cluster m...
...Search Head, 1 Deployment / License server, 1 Cluster manager and 2 Indexers. I also have a corporate network and my DMZ network. I am using the SPLUNK TA for Windows as well as the SPLUNK TA for S...
Hello Splunk Gurus, I would like to understand if Splunk has solved this problem about auto-scaling Splunk Indexer-Cluster depending upon the incoming data-volume in AWS via tools like K8s or T...
Trying to understand what the procedure would be to migrate data. Situation:
Indexer was standalone. Has standalone buckets in some of its indexes. Was added to a multisite cluster. So now some b...
...ervers I'm wondering if it's possible to create a two node cluster hosting both the search and indexing roles?
I don't think this is possible, as under the 'Cluster Nodes' guidance, it states that "M...
...hile (while documentation states that indexers within a cluster should all be the same version.)
Is it possible to split the rolling upgrade process between two business days?
If yes, should the cluster...
I have a multisite cluster with 2 sites and 2 indexers per site. I'm receiving the following error on the cluster master:
site_replication_factor={ origin:1, total:2 } is less than r...
How Splunk indexers operations works when it comes into manual detention state ? We are migrating from RHEL 6 - RHEL 8 and here can't do OS upgrade on the same machine , so we will be getting new R...
As per the documentation for adding search peers in DMC which states Do not add clustered indexers, but be sure to add clustered search heads. If you are monitoring an indexercluster and you are h...
As the title already states, It is expected to lists all indexes and not just internal ones.
I have read in other question that the possible solution is to set replication_factor to auto but not q...