Deployment Architecture

Is there a CLI command to enable or disable serach peers in Splunk 6.3.1?

basanthp
Path Finder

I have added the PROD and DR indexer hosts using add search-server CLI command. Now my requirement is to keep the PROD indexers as enabled and DR indexers as disabled. Is there a CLI command to achieve this? Do I need to disable via UI only?

0 Karma

renjith_nair
Legend

You can remove a search peer using web or CLI

splunk remove search-server -auth admin:password -url 10.10.10.10:8089

http://docs.splunk.com/Documentation/Splunk/6.2.0/DistSearch/Removeasearchpeer

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

basanthp
Path Finder

@Renjith, I am aware of the add and remove CLI commands. But my requirement is to enable or disable the search peers which has been added already. During Active-Passive switchover, I will disable the active peers and enable the passive peers (like we do in the UI -> Distributed Search -> search peers option).

0 Karma

renjith_nair
Legend

Normally for all operations from web, there should be CLI as well as configuration parameter available in splunk.

Are you looking for

splunk disable dist-search -auth admin:password

Sorry I don't have a splunk env to test it now.

./splunk help distributed
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...