QuestionQ42
Search Head Cluster Management and AdministrationAn administrator removed and then re-added search head cluster (SHC) members while patching the operating system. When attempting to re-add the first member, a script restored that SHC member to an earlier backup, and it now refuses to join the cluster.
What is the best way to repair the member so it can rejoin?
- A Force the member add by running splunk edit shcluster-config --force.
- B Review splunkd.log for configuration changes preventing the addition of the member.
- C Clean the Raft metadata using splunk clean raft.
- D Delete the [shclustering] stanza in server.conf and restart Splunk.
Community Discussion