Splunk Search

Should a search head cluster rolling restart kill searches in Splunk 6.3.0?

davebo1896
Communicator

I changed alert_actions.conf [email] in an app that is pushed to the Search Head Cluster by the deployer which initiated a rolling restart.
The rolling restart killed a search my boss was running and through some index congestion warnings.
Is this expected, or should I file a bug? Using Splunk 6.3.0

0 Karma

gjanders
SplunkTrust
SplunkTrust

Did you file a case on this ? The default for a restart appears to be a non-graceful restart of the cluster when applying a new cluster bundle or a rolling restart.

0 Karma

gjanders
SplunkTrust
SplunkTrust

I have raised an enhancement request for this feature. I had a case where a alert was running and 1 of 2 actions had fired before the restart kicked in, resulting in confusion for the user who did not receive the alert via email (which was the 2nd action)

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...