Hello,
Can someone please help me with the steps to fix it, when one of the search head in a search head cluster is down?
Thanks
Hi @Roy_9,
could you better describe your question?
your problem is understanding when a SH is down or to debug why it went down?
You can check if it's up or down, checking the presence of _internal logs from that SH.
To debug the reason because it went down, you should analyze logs in $SPLUNK_HOME/var/log/splunk to understand if there was a crash or (in splunkd.log) if some other event happened.
Ciao.
Giuseppe