<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I can not connect to the search peer in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/I-can-not-connect-to-the-search-peer/m-p/337027#M8102</link>
    <description>&lt;P&gt;Thank you for answer.&lt;BR /&gt;
It was not a problem of Splunk, it was a network problem.&lt;/P&gt;

&lt;P&gt;I want to investigate the network.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Apr 2017 08:02:00 GMT</pubDate>
    <dc:creator>kawashita_t</dc:creator>
    <dc:date>2017-04-21T08:02:00Z</dc:date>
    <item>
      <title>I can not connect to the search peer</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-can-not-connect-to-the-search-peer/m-p/337025#M8100</link>
      <description>&lt;P&gt;The following error message is output.&lt;/P&gt;

&lt;P&gt;Error Message : &lt;STRONG&gt;Problem replicating config (bundle) to search peer 'IP:Port', can't establish http connection.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I thought that the bundle size is affecting and I created the following distsearch.conf file in  / etc / sytem / local.&lt;BR /&gt;
However, it did not solve it. Also, until the other day I was able to connect without problems.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[replicationSettings]
sendRcvTimeout = 120

[replicationWhitelist]
allConf = *.conf

[replicationBlacklist]
vr = apps/app1/...
risona = apps/app2/...

[distributedSearch]
servers = &lt;A href="https://xx.xx.xx.xx:xxxx" target="test_blank"&gt;https://xx.xx.xx.xx:xxxx&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The only change is that the search peer's license was exceeded.&lt;BR /&gt;
Below is the contents of the splunkd.log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-18-2017 10:27:38.787 +0900 INFO  NetUtils - Connect timeout - waited for 60 seconds. ip=xx.xx.xx.xx port=xxxx
04-18-2017 10:27:38.787 +0900 WARN  HTTPClient - Connect to=xx.xx.xx.xx:xxxx timed out; exceeded 60sec, as per=distsearch.conf/[replicationSettings]/connectionTimeout
04-18-2017 10:27:38.787 +0900 WARN  DistributedBundleReplicationManager - Bundle upload error: Connect to=https://xx.xx.xx.xx:xxxx timed out; exceeded 60sec, as per=distsearch.conf/[replicationSettings]/connectionTimeout
04-18-2017 10:27:38.787 +0900 ERROR DistributedBundleReplicationManager - Unable to upload bundle to peer named splunk01 with uri=https://xx.xx.xx.xx:xxxx.
04-18-2017 10:27:38.787 +0900 WARN  DistributedBundleReplicationManager - Asynchronous bundle replication to 1 peer(s) succeeded; however it took too long (longer than 10 seconds): elapsed_ms=63086, tar_elapsed_ms=2136, bundle_file_size=126300KB, replication_id=1492478795, replication_reason="async replication allowed"
04-18-2017 10:27:38.787 +0900 WARN  DispatchReaper - Spent 35559ms reaping bundle tarballs in $SPLUNK_HOME/var/run
04-18-2017 10:27:38.789 +0900 INFO  PipelineComponent - MetricsManager:probeandreport() took longer than seems reasonable (61310 milliseconds) in callbackRunnerThread. Might indicate hardware or splunk limitations.
04-18-2017 10:28:01.174 +0900 WARN  DistributedPeerManager - Unable to distribute to peer named splunk01 at uri &lt;A href="https://xx.xx.xx.xx:xxxx" target="test_blank"&gt;https://xx.xx.xx.xx:xxxx&lt;/A&gt; because replication was unsuccessful. replicationStatus Failed failure info: failed_because_HTTP_CONNECTION_FAILURE
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 18 Apr 2017 01:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-can-not-connect-to-the-search-peer/m-p/337025#M8100</guid>
      <dc:creator>kawashita_t</dc:creator>
      <dc:date>2017-04-18T01:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: I can not connect to the search peer</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-can-not-connect-to-the-search-peer/m-p/337026#M8101</link>
      <description>&lt;P&gt;Delete the search peer from your distributed search config (in splunk web), then add the search peer back in.  Does the replication succeed after this?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 13:27:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-can-not-connect-to-the-search-peer/m-p/337026#M8101</guid>
      <dc:creator>suarezry</dc:creator>
      <dc:date>2017-04-18T13:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: I can not connect to the search peer</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/I-can-not-connect-to-the-search-peer/m-p/337027#M8102</link>
      <description>&lt;P&gt;Thank you for answer.&lt;BR /&gt;
It was not a problem of Splunk, it was a network problem.&lt;/P&gt;

&lt;P&gt;I want to investigate the network.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 08:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/I-can-not-connect-to-the-search-peer/m-p/337027#M8102</guid>
      <dc:creator>kawashita_t</dc:creator>
      <dc:date>2017-04-21T08:02:00Z</dc:date>
    </item>
  </channel>
</rss>

