I'm a Splunk PS admin working at a client site and I wanted to post a challenge and resolution that we encountered.
Client reported missing knowledge objects in a custom app private area; they expected ~40 reports but only had ~17. The client last used the reports 7 days prior. Asked Splunk PS to investigate.
3 instance SHC
Version 8.2.3, Linux
>50 users across the platform
That's an awesome explanation @NullZero.... We are facing similar issues, but sort of different way...
We have 2 node Search Head Cluster... among which one is static captain... another one is a member.
Often the non-captain member goes out of cluster (It is not showing in the Search head clustering page).. every time we are manually restarting the Splunk or the entire EC2 of the member.. then it is showing in the cluster page....
Can i use the re-sync command to solve the issue, instead of restarting the Splunk or EC2? will it help?
Thanks for your help 😊