A non-clustered Splunk environment has three indexers (A,B,C) and two search heads (X, Y). During a search executed on search head X, indexer A crashes. What is Splunk's response?
This is explained in the Splunk documentation1, which states:
If an indexer goes down during a search, the search head notifies you that the results might be incomplete. The search head does not attempt to re-run the search on another indexer.
Kenneth
1 day agoLinette
6 days agoMattie
11 days agoNovella
17 days agoBen
22 days agoPeggie
27 days agoAllene
2 months agoJessenia
2 months agoKristel
2 months agoAron
2 months agoTijuana
2 months agoDeane
2 months agoAlexia
3 months agoAnnamaria
3 months agoViva
3 months agoVeta
3 months agoGeraldine
3 months agoEffie
3 months agoTammy
4 months agoTyra
4 months agoLashawn
4 months agoMatthew
4 months agoJesusa
4 months agoJules
5 months agoDevora
5 months ago