Splunk® Enterprise

Managing Indexers and Clusters of Indexers

Download manual as PDF

Splunk Enterprise version 5.0 reached its End of Life on December 1, 2017. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

How cluster nodes start up

This topic describes what happens when:

  • the master node starts
  • a peer node joins a new cluster
  • a peer node joins an existing cluster

When the master node starts

When a master node comes online (either the first time or subsequently), it begins listening for cluster peers. Each online peer registers with the master, and the master adds it to the cluster. The master waits until the replication factor number of peers register, and then it starts performing its functions.

When you first deploy the cluster, you must enable the master before enabling the peer nodes, as described in "Deployment overview". The master blocks indexing on the peers until you enable and restart the full replication factor number of peers.

If you subsequently restart the master, it waits for a quiet period of 60 seconds, so that all peers have an opportunity to register with it. Once the quiet period ends and the replication factor number of peers have registered with it, the master can start performing its coordinating functions, such as telling peers where to stream copies of incoming data. Therefore, you must make sure that there are at least replication factor number of peers running when you restart the master.

After the 60 second quiet period is over, you can view the master dashboard for accurate information on the status of the cluster.

For more information on what occurs when a master goes down and then restarts, see "What happens when a master node goes down".

When a peer joins a new cluster

When you initially deploy a cluster, you must first enable the master and then enable the peer nodes, as described in "Deployment overview". The master blocks indexing on the peers until you enable and restart the full replication factor number of peers.

Each peer registers with the master when it comes online, and the master automatically distributes the latest configuration bundle to it. The peer then validates the configuration bundle locally. The peer will only join the cluster if bundle validation succeeds.

The peer starts indexing data after the replication factor number of peers join the cluster.

When a peer joins an existing cluster

A peer can also come online at some later time, when the cluster is already up and running with a master and the replication factor number of peers. The peer registers with the master when it comes online, and the master automatically distributes the latest configuration bundle to it. The peer then validates the configuration bundle locally. The peer will only join the cluster if bundle validation succeeds.

Note: Adding a new peer to an existing cluster does not result in any immediate rebalancing of buckets. The peer can participate in future bucket replication, but the master does not automatically shift bucket copies or resassign primaries from existing peers to the new peer.

PREVIOUS
How clustered search works
  NEXT
What happens when a peer node goes down

This documentation applies to the following versions of Splunk® Enterprise: 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters