Installation

How can convert the replication factor raw log to searchable data in index cluster

msplunk33
Path Finder

How can convert the replication factor raw log to searchable data incase the searchable data is not available in a indexer. Is this a automated process by indexer or manual process.

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

this is automated process, which starts after CM has realized that one node is missing from cluster. Unfortunately I couldn’t found any good presentation of this. There are at least in some training materials where this was clearly presented.

r. Ismo

0 Karma

msplunk33
Path Finder

@isoutamo  Do you mean one node completely fail or just unresponsive. when CM start this process What is the  process of restoring a comply failed node after a failure. How about the previous log this node was storing will it be automatically restored if we rejoin this node as a new fresh node with same disc structure. Do we need to manually copy the old log.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Here is described what and how bucket fixing has done when peers go offline.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Indexer/Whathappenswhenaslavenodegoesdown

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...