Splunk Enterprise

Powering down Indexers for maintenance

np_hwp
Engager

We have four indexers in a cluster, single site, with RF=3 and SF=2. 

We will have a maintenance that will require two indexers power down (EC2 instances), and the maintenance will last about two hours. 

What will be the proper way or sequence for taking those two indexer servers power down? 

Should I do splunk offline on one indexer first, power down, wait for a while, and then proceed to other indexer? 

or should I do splunk offline on both servers , and power down simultaneously?  

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

splunk offline is not recommended for two hours long. 
you can enable maintenance-mode on cluster master.

you can do below:

  • stop the Splunk Indexer
  • disable boot-start (if you need to do multiple restart during your maintenance, this will avoid starting of splunk service)
  • once you are done with activity you can start splunk and enable boot-start.

you can do same for other Indexer at the same time.

once you are done with activity on both servers. You can enable maintenance-mode on cluster master.

————————————
If this helps, give a like below.

richgalloway
SplunkTrust
SplunkTrust
It's better to do one at a time, if you can. Bring the first back up before taking the other one down.
If they both have to be down at the same time, then IMO it's better bring them both down at about the same time. That will keep the CM from moving primary buckets to the indexer that's next to go down.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...