Deployment Architecture

How to clean up a search head in a search head cluster?

sarahnazzar
Explorer

Hi Guys,

It would be helpful if anyone shares knowledge/provide steps about cleaning up a search head in a search head cluster environment.
I want to know what is cleaned up and what's the process and all.

Thanks in Advance!!
Sarah

0 Karma

sarahnazzar
Explorer

Actually my issue is when I push some changes to Search head cluster via deployer, those changes are not reflecting in some search heads and all the search heads are not in proper sync. So exploring about clean up.

Below is the error for reference,
Search head cluster member (https://xx.xx.xx.xx:xxxx) is having problems pushing configurations to the search head cluster captain (https://xx.xx.xx.xx:xxxx). Changes on this member are not replicating to other members.

0 Karma

wmyersas
Builder

If you have a good deployment strategy, the simplest thing to do is nuke-pave-reinstall the "misbehaving" cluster members

0 Karma

burwell
SplunkTrust
SplunkTrust

Hello. Can you say more about what you want to have cleaned up?

Are you talking about removing the knowledge objects? Scheduled searches? Users?

sarahnazzar
Explorer

I want to know if we clean up what will be removed from the Search head.. either everything present in the Search head or particular thing as you have mentioned(knowledge objects, Scheduled searches, Users etc..)

Also, It would be helpful if I get some steps regarding this.

0 Karma

sarahnazzar
Explorer

I'm getting below error, so was exploring about clean up and stuffs..

Search head cluster member (https://xx.xx.xxx.xx:xxxxx) is having problems pushing configurations to the search head cluster captain (https://xx.xx.xxx.xx:xxxxx). Changes on this member are not replicating to other members.

And If I push any changes via deployer, its not getting reflected on some of the search heads because of this.

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...