Hello,
I have a 3-node (Windows 2012 R2 based) Search Head Cluster currently connected to a standalone indexer.
I wanted to follow the non-rolling upgrade procedure (anticipating it will be s...
...eployer and I can do arollingrestartof the search head members, but the indexers must be brought down all at once. Am I missing something in the docs? Or is it acceptable to somehow combine the two b...
Hi all,
We have in our productive splunk architecture a very unpleasant problem.
The rolling-restart behaves not as he should. Be it creating anindex or otherwise. In arolling-restart, e...
When Cluster Master initiates arestart either by "splunk apply cluster-bundle" or "splunk rolling-restartcluster-peers" many of the indexers fails to restart - the server is told to restart, it s...
...ustomindexname/rebuild-metadata-and-manifests)
5) Performed rollingrestart from Cluster Master and all indexers went down.
6) After issue checked .bucketManifest file and found that "origin_site" header w...
...alidation
splunk@ulvlfimw01:~/bin> /opt/splunk/splunk/bin/splunk apply cluster-bundle
Warning: Under some circumstances, this command will initiate arollingrestartofall peers. This d...
...pgradeyourdistributedSplunkEnterpriseenvironment
first document says all Indexers should be stopped and upgraded at the same time:
Upgrade a 6.x indexercluster to a later version of 6.x When you upgrade a 6.x indexercluster, such as 6...
I read that in 8.1.2 it's less painful to update HEC configs, no longer requiring arestart for CRUD operations. Should I keep my HEC on HWF or move it directly to indexers?
We have in indexcluster:
two node indexcluster
two sites (one index peer in each site)
We are seeing an issue whereby rollingrestarts of our indexcluster is causing indexing issues o...
...imply make the changes live; no restart. We are finding that much of the capability to make those sorts of changes without the indexers restarting are now gone since moving to clustering. While arolling...