Closed aleoliva closed 4 years ago
Install Splunk 8.0: Splunk 8.0 does use a new internal index (_metrics), which needs to be part of the base configs indexes.conf. Otherwise the Cluster does not work. The Base Config app (org_all_indexes) has been updated, please download them again to do the Splunk 8 installation.
Upgrade to Splunk 8.0: The Upgrade playbook needs to be changed. There is a special upgrade procedure needed for upgrades to 8.0, when running with systemd, see Upgrade considerations for systemd
After downloading the new _org_allindexes, a fresh installation of Splunk v8.0 looks successful. The point 1 looks solved.
I have updated the upgrade playbook to support Splunk 8.x now. Please test.
When I tested, the task:
failed for one (and only one) of the servers, a SearchHeader (splp0sh000.splunk.sbb.ch).
Attached ansible.log.gz, with further details.
First of all, I need to clarify on the usage of the upgrade.yml playbook. This playbook is not intended to you globally for all the nodes at the same time. The upgrade procedure for the different nodes needs to be followed according to the docs. The playbook is not taking care about that. It does only care about the upgrade of the Splunk software on an individual node, but not the order or the maintenance state are similar. An Upgrade szenario could be handled like documented here: Dist Upgrade Example
For the error, it's not quite clear to me, what is broken. The only thing I could see, was that the systemd configuration might be not setup correctly during installation, since it does not detect systemd usage for this particular host:
2019-11-12 16:10:22,556 p=28626 u=ue60876 | TASK [splunk_common : set use_splunk_systemd] ****************************************************************************************************************************
2019-11-12 16:10:22,877 p=28626 u=ue60876 | skipping: [splp0sh000.splunk.sbb.ch]
Thanks about the Upgrade scenario. Fortunately, we are on a development phase without load, therefore we can proceed upgrades in parallel without worrying about service disruptions.
About the error specifically, sure splp0sh000 had systemd
setup for Splunk. We can try to reproduce the error again (not sure if we can do it), which information would be useful for you?
Regards
The error, reported on previous #issuecomment-552940073, never reappeared.
We consider that it was an isolate case and we suggest to close this issue, since works good with version 8.0 now
Describe the bug The installation of Splunk v8.0.0 with Splunkenizer was unsuccessful.
1.- When we tried a fresh installation with
ansible/deploy_site.yml
, the playbook finished successfully however the Indexers were not registered.2.- When we tried an upgrade, with
ansible/ugrade_splunk.yml
, the playbook failed because it couldn't restartsplunkd
.Expected behavior In Case 1 we expected this output:
However we receive this other one:
In Case 2, the playbook is interrupted with this error on all target servers:
Inside the servers, we can get this information:
Workaround The Case 2 can be solved and get Splunk running without issues, after running these commands:
Desktop (please complete the following information):
Additional context For Case 1 next logs have been attached:
For Case 2 next logs have been attached: