QuestionQ162

KV Store Collection and Lookup Management

Which command should you run to resynchronize a stale KV Store member in a search head cluster?

  • A splunk clean eventdata -local
  • B splunk clean kvstore - local
  • C splunk resync kvstore -local
  • D splunk resync kvstore -remote
Explanation

For an individual stale KV Store member, Splunk directs you to stop the affected search head, clean its local KV Store data, and restart it. On restart, the member performs an initial synchronization from the healthy KV Store members. The cluster-wide resync kvstore command is instead run from the search head cluster captain to recreate and resynchronize the cluster when necessary.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!