Splunk Search Head Cluster Setup

Use when the user asks to bootstrap an SHC, push a deployer bundle, perform a searchable rolling restart, transfer the captain, add or remove a member, troubleshoot KV Store replication lag, migrate a standalone search head to SHC, or replace a deployer. Render, preflight, apply, validate, and operate Splunk Enterprise Search Head Clusters end-to-end: bootstrap (deployer + N-member init + captain election), deployer bundle push (validate / status / apply / apply-skip-validation / rollback with SHA and generation-drift tracking), rolling restart (default, searchable with health-check loop, forced), captain transfer, member add / decommission / remove, KV Store replication health (lag thresholds, oplog reset, captain re-election), standalone-to-SHC migration, deployer replacement, ES-on-SHC deployer placement, and failure-mode runbooks (split-brain, quorum loss, deployer mismatch, captain crash loop). SHC pass4SymmKey is templated as `$SHC_SECRET` for operator-managed rotation (see Out of Scope).

chambear2809 Updated

File contents

chambear2809/splunk-cisco-skills/tree/main/skills/splunk-search-head-cluster-setup commit 9cac510eca

Frequently asked questions

npx skillmds@latest add chambear2809/splunk-search-head-cluster-setup