<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error when pushing cluster bundle to SHs in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/759704#M24061</link>
    <description>&lt;P&gt;This is the resolution:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Error-503-Splunkd-daemon-cannot-be-reached-by-Splunk-Web-after-upgrade-to-9-4-8-10-x-versions" target="_blank"&gt;Error 503 : Oops Splunkd daemon cannot be reached by Splunk Web after upgrade to 9.4.8/ 10.x versions | Splunk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Resolution
The issue is resolved after updating the server.conf configuration, by leaving the two added parameter values as blank. 


[applicationsManagement]
splunkbaseAppsDumpUrl=
archivedSplunkbaseAppsDumpUrl=

Fix is included in the following versions of Splunk Enterprise:
9.3.11, 9.4.10,10.0.5,10.2.2&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 26 Mar 2026 19:02:03 GMT</pubDate>
    <dc:creator>JohnEGones</dc:creator>
    <dc:date>2026-03-26T19:02:03Z</dc:date>
    <item>
      <title>Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758583#M23915</link>
      <description>&lt;P&gt;Seeing this error on SHC-D when attempting to push bundle to SHs:&lt;/P&gt;&lt;P&gt;Error while deploying apps to first member, aborting apps deployment to all members: Error while fetching apps baseline on target=https://&amp;lt;IP address of SH Cluster Captain&amp;gt;:8089: Network-layer error: Read Timeout&lt;/P&gt;&lt;P&gt;All servers are running Splunk Enterprise 9.4.8&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2026 19:21:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758583#M23915</guid>
      <dc:creator>SplunkNinja</dc:creator>
      <dc:date>2026-02-20T19:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758584#M23916</link>
      <description>&lt;P&gt;Also - it seems that the SHs may be in a rolling restart loop?&amp;nbsp; splunk show shcluster-status --verbose shows the following:&lt;/P&gt;&lt;P&gt;rolling_restart : restart&lt;/P&gt;&lt;P&gt;status : Up -&amp;gt;&amp;nbsp;status : Pending -&amp;gt;&amp;nbsp;status : Up&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2026 19:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758584#M23916</guid>
      <dc:creator>SplunkNinja</dc:creator>
      <dc:date>2026-02-20T19:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758592#M23918</link>
      <description>&lt;P class="lia-align-left"&gt;I am hoping this is of help, never really ran into this problem, but I would say the fact that you have a constant rolling restart of your search heads is probably not a good thing.&amp;nbsp; So one of the things I had happen to me a long time ago, was I pushed a bad config to my search head cluster and it got stuck in that constant rolling restart.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I ultimately was able to fix it by shutting down the whole cluster, bringing up one machine, getting that config file fixed and then moving onto the next search head.&amp;nbsp; Not sure if you do or do not have a bad config and I am sure this is not a great idea in a production environment.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If the search heads are still working - then you may not want to try this method, but if they aren't working, bringing them all down doesn't technically make things worse.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I wish I had a better answer for what exactly you need to change to get the machines to stop rolling restarting, but maybe my above suggesiton of bringing it down and then restarting it from the CLI and look for any errors in the start up or in the splunk internal logs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2026 00:17:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758592#M23918</guid>
      <dc:creator>LAME-Creations</dc:creator>
      <dc:date>2026-02-21T00:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758600#M23920</link>
      <description>&lt;P&gt;Firstly, browse through all member SHs and check if they are indeed in a restart loop. If they are, you gotta dig into the logs why are the SH(s) restarting. But they might not be and the message might be just because of network (or TLS!) problems.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Feb 2026 15:35:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758600#M23920</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-02-21T15:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758659#M23928</link>
      <description>&lt;P&gt;After reviewing again, the SHs were not restarting.&amp;nbsp; There was an issue with the SH replication port which I since fixed.&amp;nbsp; So now all the SHs show status: up.&amp;nbsp; But I am still having an issue with pushing a bundle.&amp;nbsp; I even removed all the current shcluster apps to a tmp directory and I created a dummy app and tried to push this with no luck.&lt;/P&gt;&lt;P&gt;mkdir -p /opt/splunk/etc/shcluster/apps/_dummy_app/local&lt;BR /&gt;echo "[ui]" &amp;gt; /opt/splunk/etc/shcluster/apps/_dummy_app/local/app.conf&lt;BR /&gt;echo "is_visible = false" &amp;gt;&amp;gt; /opt/splunk/etc/shcluster/apps/_dummy_app/local/app.conf&lt;/P&gt;&lt;P&gt;sudo chown -R splunk:splunk /opt/splunk&lt;/P&gt;&lt;P&gt;Error while deploying apps to target=https://&amp;lt;SH-02&amp;gt;:8089 with members=3: Error while fetching apps baseline on target=https://&amp;lt;SH-02&amp;gt;:8089: Network-layer error: Read Timeout, Error while fetching apps baseline on target=https://&amp;lt;SH-03&amp;gt;:8089: Network-layer error: Read Timeout&lt;/P&gt;&lt;P&gt;I also do not think this is a network or port issue since I can use this openssl command from the deployer to any of the SHs and I get what looks like a normal response.&amp;nbsp; I can also use the same command on SHs to the other SHs.&lt;/P&gt;&lt;P&gt;openssl s_client -connect &amp;lt;IP address of SH&amp;gt;:8089&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure what to try next.&amp;nbsp; Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 00:10:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758659#M23928</guid>
      <dc:creator>SplunkNinja</dc:creator>
      <dc:date>2026-02-24T00:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758672#M23929</link>
      <description>&lt;P&gt;Did you ever find a solution to this? Im having the same issue now when pushing sh cluster bundle after upgrading to Splunk 9.4.8.&lt;BR /&gt;The SHs are not restarting, status is up and ports are open. Everything appears to be normal.&lt;/P&gt;&lt;P&gt;Im using Ansible to trigger the bundle push, and the ansible job just "hangs" for 10 minutes before returning the error.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 13:19:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758672#M23929</guid>
      <dc:creator>Zzyzx</dc:creator>
      <dc:date>2026-02-24T13:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758841#M23950</link>
      <description>&lt;P&gt;I did not find a fix to this.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2026 22:43:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/758841#M23950</guid>
      <dc:creator>SplunkNinja</dc:creator>
      <dc:date>2026-02-26T22:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/759702#M24060</link>
      <description>&lt;P&gt;I have run into this issue, and support has been struggling a bit here. These all started with the upgrade from 9.4.4 to 9.4.8.&lt;BR /&gt;&lt;BR /&gt;9.4.8 lists this in Known Issues&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Splunk WebUI and bundle push are not working correctly on stacks that are unable to fetch application dumps

Workaround:
Edit $SPLUNK_HOME/etc/system/local/server.conf, and set the below parameters values as blank: [applicationsManagement] splunkbaseAppsDumpUrl= archivedSplunkbaseAppsDumpUrl=
Then restart the modified instances (Splunk Web). Clearing those values prevents unreachable calls to the applications dumps and restores UI responsiveness and other functionalities that rely on apps listing.&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;I'll send an update when I get a firm resolution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2026 18:27:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/759702#M24060</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2026-03-26T18:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/759704#M24061</link>
      <description>&lt;P&gt;This is the resolution:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Error-503-Splunkd-daemon-cannot-be-reached-by-Splunk-Web-after-upgrade-to-9-4-8-10-x-versions" target="_blank"&gt;Error 503 : Oops Splunkd daemon cannot be reached by Splunk Web after upgrade to 9.4.8/ 10.x versions | Splunk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Resolution
The issue is resolved after updating the server.conf configuration, by leaving the two added parameter values as blank. 


[applicationsManagement]
splunkbaseAppsDumpUrl=
archivedSplunkbaseAppsDumpUrl=

Fix is included in the following versions of Splunk Enterprise:
9.3.11, 9.4.10,10.0.5,10.2.2&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 26 Mar 2026 19:02:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/759704#M24061</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2026-03-26T19:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/759737#M24063</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258618"&gt;@JohnEGones&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315860"&gt;@Zzyzx&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/311050"&gt;@LAME-Creations&lt;/a&gt;&amp;nbsp; I was able to follow this KB and it helped solve the issue for me&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Deployer fails to push a bundle to Search Head Cluster Peers in 9.4.1 (default apps)&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Deployer-fails-to-push-a-bundle-to-Search-Head-Cluster-Peers-in-9-4-1" target="_blank" rel="noopener"&gt;https://splunk.my.site.com/customer/s/article/Deployer-fails-to-push-a-bundle-to-Search-Head-Cluster-Peers-in-9-4-1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Changing the command arguments as per this Splunk KB Article prompted the Deployer to create a fresh staging directory, bypassing the stale/corrupt one that was causing the error.&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/bin/splunk apply shcluster-bundle -target &amp;lt;URI&amp;gt;:&amp;lt;management_port&amp;gt; -push-default-apps true&lt;/P&gt;&lt;P&gt;Also - I could have run this command to clear out the old/bad bundle...&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;rm -rf $SPLUNK_HOME/var/run/splunk/deploy*&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2026 15:30:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/759737#M24063</guid>
      <dc:creator>SplunkNinja</dc:creator>
      <dc:date>2026-03-27T15:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Error when pushing cluster bundle to SHs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/759745#M24064</link>
      <description>&lt;P&gt;See my latest message.&amp;nbsp; Also - I could have run this command to clear out the old/bad bundle...&lt;/P&gt;&lt;PRE class="language-plaintext"&gt;&lt;CODE&gt;rm -rf $SPLUNK_HOME/var/run/splunk/deploy*&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 27 Mar 2026 15:20:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-when-pushing-cluster-bundle-to-SHs/m-p/759745#M24064</guid>
      <dc:creator>SplunkNinja</dc:creator>
      <dc:date>2026-03-27T15:20:56Z</dc:date>
    </item>
  </channel>
</rss>

