Splunk Enterprise

Regarding my search head cluster

satyaallaparthi
Communicator

Hello,

I have 2 search heads (sh), 2 indexers, 1 heavy forwarder, and 1 deployment in my environment.

The deployment is acting as a cluster master for SH and indexer and SH1 is acting as a captain.
But I got a problem now with that.. SH 1, that is SH captain replication status, is showing initial, and SH member replication status is showing successful. I tried a lot but didn’t get successful results.

Can anyone help me with that? Thanks in advance.

Splunk Version 7.1.1

Tags (2)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

You need at minimum 3 search heads to elect a captain. Because you only have 2, that is your problem. Add another search head and the issue will go away.

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

You need at minimum 3 search heads to elect a captain. Because you only have 2, that is your problem. Add another search head and the issue will go away.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...