Just reporting back on this for others. This actually went really well for us. For more context, we have 10 indexers on each site with around 45K buckets on each indexer. We are also on version 9.4.1. We had one site down for about 9 hours while our data center performed maintenance. Before the maintenance, we put CM in MM, offlined the indexers one at a time (with bin/splunk offline) waiting for a "Restarting" status before proceeding to the next indexer. Once the data center maintenance was complete, we started Splunk up on all indexers at once, waited for an "Up" status for all indexers in the CM UI, and then took CM out of MM. The fixup time was less than 30 minutes, which is better than we expected. We have noticed that our current version of 9.4.1 seems to be more efficient with fixup than some of our previous versions.
... View more