We would like to inquire about a communication issue between the Search Head and Indexers that occurred after cluster recovery. Environment Splunk Enterprise 9.3.3 Indexer Cluster (3 Indexers) Search Head environment Background In our environment, we experienced an issue where the Indexer Cluster did not recover properly after all Indexers had been shut down. Originally, indexes.conf had been deployed directly on each Indexer. As part of our investigation and remediation efforts, we changed the configuration so that indexes.conf would be managed under the Cluster Manager, which successfully restored the Indexer Cluster. After the cluster itself returned to a healthy state, a new issue occurred in which search communications from the Search Head to the Indexers were no longer functioning correctly. During troubleshooting, we temporarily interrupted connectivity on TCP/9997 at the Indexer side and then re-established the connection. After doing so, communication between the Search Head and Indexers recovered successfully. Questions ① Are there any known issues where Search Head-to-Indexer communication fails to re-establish properly after Indexer Cluster recovery? ★ ② Since the issue was resolved after reconnecting TCP/9997, could stale connection information, session inconsistencies, or cached communication states have been a contributing factor? ③ Following a full shutdown and recovery of all Indexers in an Indexer Cluster, are there any additional steps or recommended procedures that should be performed on the Search Head, Deployer, or Cluster Manager? ★ ④ Based on the information provided, are there any likely root causes that Splunk Support would recommend investigating further? Questions marked with a ★ are high-priority items. If possible, we would appreciate it if you could address these points first.
... View more