Indexer Cluster Rolling Upgrade and Long-Running Search Continuity
0 reputation · 01 Nov 2024, 14:32 UTC
Rolling Upgrade Behavior
Splunk indexer clusters support rolling upgrades to maintain availability by taking individual nodes offline sequentially. While this process ensures the cluster remains operational for new data ingestion and new search requests, the impact on active, long-running search jobs is not fully defined across different versions.
Search Job Persistence
When a search head targets a specific indexer that is stopped for an upgrade, the cluster's failover mechanism manages the request. However, there is uncertainty regarding whether a search already in progress on the node being upgraded is automatically redirected to remaining peers or if the job is terminated.
This behavior is critical for environments running complex reports or large-scale data migrations that require extended execution times without interruption.
- Does Splunk Enterprise 9.x support the seamless redirection of an active search job if the hosting indexer is taken offline during a rolling upgrade?
- What is the specific threshold of active indexers required to prevent search job timeouts during this process?