Deployment Architecture

How do I disable the system configurations in the search head cluster?

davebo1896
Communicator

I enabled the system configurations in the search head cluster.

How do I disable them so they don't show up any more?

0 Karma
1 Solution

davebo1896
Communicator

Splunk Support gave me the correct answer. Rolling restart of the SHC resets the confgurations, so you no longer see the system level configs in the UI.

View solution in original post

Steve_G_
Splunk Employee
Splunk Employee

Actually, it is not necessary to perform a rolling restart of the entire cluster. You merely need to restart the instance(s) on which you previously exposed the system settings (via the "Show All Settings button).

This is documented here: http://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/HowconfigurationworksinSHC#The_Settings...

davebo1896
Communicator

How would I know which instance that was?

0 Karma

Steve_G_
Splunk Employee
Splunk Employee

The system-level settings will only appear on those instances where you clicked "Show All Settings."

davebo1896
Communicator

I don't know which instance I am on, in a Search Head Cluster.

0 Karma

Steve_G_
Splunk Employee
Splunk Employee

Presumably that's because you're accessing the cluster members from a load balancer. To determine the instance, the best approach would be to log into the members directly.

On the other hand, you can do as you did, which was to restart all instances. But it seems unnecessarily inconvenient to restart them all, when restarting just one would handle the need.

0 Karma

davebo1896
Communicator

Splunk Support gave me the correct answer. Rolling restart of the SHC resets the confgurations, so you no longer see the system level configs in the UI.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...