<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Distributed search peer not working as expected. There are multiple errors logs in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452084#M15870</link>
    <description>&lt;P&gt;Just laksman239 says, we need a little more info.  What kind of load do you have on your systems?  How is memory and CPU doing on your SH's and indexers?  How many searches are happening at any one moment?  You can check all of this in your DMC or "Monitoring" console (Settings -&amp;gt; DMC or Monitoring).  &lt;/P&gt;</description>
    <pubDate>Mon, 04 Feb 2019 15:34:18 GMT</pubDate>
    <dc:creator>BainM</dc:creator>
    <dc:date>2019-02-04T15:34:18Z</dc:date>
    <item>
      <title>Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452082#M15868</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;We have 4 search head (non clustered) and 16 search peers (non clustered) . Each search head points to all 16 search peers. &lt;/P&gt;

&lt;P&gt;Recently one of our search head was getting freeze and  no search was working. So we tried disabling and enabling the search peers the problem was still the same. So while testing we disabled first three search peers and the search started working. &lt;/P&gt;

&lt;P&gt;But now though the search is working but when we try to enable any one or all three disabled search peers the search head again gets freeze and no search works.&lt;/P&gt;

&lt;P&gt;I have tried restarting the search head and peers but no improvement.&lt;BR /&gt;
Deleted and added the search peers in config file from server still no improvement.&lt;/P&gt;

&lt;P&gt;Below are the errors logs i have noted on search head for those peers. All the disabled peers have similar error logs:&lt;/P&gt;

&lt;P&gt;01-02-2019 02:12:06.146 +0100 WARN  DistributedPeerManager - Unable to distribute to peer named &lt;BR /&gt;
at uri= using the uri-scheme=https because peer has status="Down".  Please verify uri-scheme, &lt;BR /&gt;
connectivity to the search peer, that the search peer is up, and an adequate level of system resources are available.&lt;BR /&gt;
 See the Troubleshooting Manual for more information.&lt;/P&gt;

&lt;P&gt;01-02-2019 02:11:35.352 +0100 WARN  DistributedPeer - Peer: &lt;BR /&gt;
Unable to get server info from services/server/info due to: &lt;BR /&gt;
Connect Timeout; exceeded 10000 milliseconds&lt;/P&gt;

&lt;P&gt;01-02-2019 02:10:24.314 +0100 INFO  StatusMgr - destHost=, destIp=, destPort=9997,&lt;BR /&gt;
 eventType=connect_fail, publisher=tcpout, sourcePort=8089, statusee=TcpOutputProcessor&lt;/P&gt;

&lt;P&gt;01-02-2019 01:38:01.074 +0100 WARN  DistributedBundleReplicationManager - replicateDelta: failed for peer=, &lt;BR /&gt;
 uri=, &lt;BR /&gt;
 cur_time=1546386051, cur_checksum=1546386051, prev_time=1546381229, prev_checksum=4121658182606070965, &lt;BR /&gt;
 delta=/opt/splunk/var/run/-1546381229-1546386051.delta&lt;/P&gt;

&lt;P&gt;01-02-2019 01:38:01.074 +0100 ERROR DistributedBundleReplicationManager - Reading reply to upload: rv=-2,&lt;BR /&gt;
 Receive from= timed out; exceeded 60sec, &lt;BR /&gt;
 as per=distsearch.conf/[replicationSettings]/sendRcvTimeout&lt;/P&gt;

&lt;P&gt;01-02-2019 01:36:04.709 +0100 WARN  DistributedPeerManager - Unable to distribute to peer named at &lt;BR /&gt;
 uri  because replication was unsuccessful. &lt;BR /&gt;
 replicationStatus Failed failure info: failed_because_BUNDLE_DATA_TRANSMIT_FAILURE&lt;/P&gt;

&lt;P&gt;11-07-2018 10:51:07.007 +0100 WARN  DistributedPeer - Peer: Unable to get bundle list&lt;/P&gt;

&lt;P&gt;11-27-2018 20:12:16.688 +0100 WARN  DistributedPeer - Peer: &lt;BR /&gt;
 Unable to get server info from /services/server/info due to: No route to host&lt;/P&gt;

&lt;P&gt;Any kind of help will be really helpful.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Umesh&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:08:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452082#M15868</guid>
      <dc:creator>umeshagarwal008</dc:creator>
      <dc:date>2020-09-29T23:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452083#M15869</link>
      <description>&lt;P&gt;did you check the connectivity from the SH to indexers on the required ports? [.e.g 8089] Any chance, this was broken in the recent past or the servers moved to a diff network segment [ IP address] and hence connectivity takes longer and times out?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 15:05:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452083#M15869</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-04T15:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452084#M15870</link>
      <description>&lt;P&gt;Just laksman239 says, we need a little more info.  What kind of load do you have on your systems?  How is memory and CPU doing on your SH's and indexers?  How many searches are happening at any one moment?  You can check all of this in your DMC or "Monitoring" console (Settings -&amp;gt; DMC or Monitoring).  &lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 15:34:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452084#M15870</guid>
      <dc:creator>BainM</dc:creator>
      <dc:date>2019-02-04T15:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452085#M15871</link>
      <description>&lt;P&gt;Sure let me gather these information and share with you. &lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 15:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452085#M15871</guid>
      <dc:creator>umeshagarwal008</dc:creator>
      <dc:date>2019-02-04T15:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452086#M15872</link>
      <description>&lt;P&gt;Open a case with support.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 21:08:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452086#M15872</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-04T21:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452087#M15873</link>
      <description>&lt;P&gt;Everything looks good on DMC. After further investigation looks like the issue is with Bundle replication. &lt;BR /&gt;
I am trying to copy one set of bundle from a working search peer to disabled search peer for that search-head and see if it works.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 08:32:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452087#M15873</guid>
      <dc:creator>umeshagarwal008</dc:creator>
      <dc:date>2019-02-06T08:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452088#M15874</link>
      <description>&lt;P&gt;Yes that the last option we have. &lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 08:33:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452088#M15874</guid>
      <dc:creator>umeshagarwal008</dc:creator>
      <dc:date>2019-02-06T08:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452089#M15875</link>
      <description>&lt;P&gt;As @lakshman239 mentioned, this looks like network issue because Connection timed out and No route to host error generally occur when there is firewall block or routing issue.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 09:43:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452089#M15875</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-02-06T09:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452090#M15876</link>
      <description>&lt;P&gt;02-06-2019 11:14:24.183 +0100 INFO  StatusMgr - destHost=, destIp=, destPort=9997, eventType=connect_done, publisher=tcpout, sourcePort=8089, statusee=TcpOutputProcessor&lt;/P&gt;

&lt;P&gt;This it the current status &lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 10:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452090#M15876</guid>
      <dc:creator>umeshagarwal008</dc:creator>
      <dc:date>2019-02-06T10:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452091#M15877</link>
      <description>&lt;P&gt;Can you please try to telnet from Search Head to Indexer on Port 8089 ?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 10:53:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452091#M15877</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-02-06T10:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452092#M15878</link>
      <description>&lt;P&gt;Just checked. Its getting connected.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 11:04:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452092#M15878</guid>
      <dc:creator>umeshagarwal008</dc:creator>
      <dc:date>2019-02-06T11:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452093#M15879</link>
      <description>&lt;P&gt;Trying ...&lt;BR /&gt;
Connected to (URL)&lt;BR /&gt;
Escape character is '^]'.&lt;BR /&gt;
Connection closed by foreign host.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 11:06:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452093#M15879</guid>
      <dc:creator>umeshagarwal008</dc:creator>
      <dc:date>2019-02-06T11:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452094#M15880</link>
      <description>&lt;P&gt;Pls go through &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/DistSearch/Limittheknowledgebundlesize"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/DistSearch/Limittheknowledgebundlesize&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Whatsearchheadssend"&gt;https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Whatsearchheadssend&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Sometime, your search head may try to send a lot of large CSV files and apps/conf's that are not needed for the indexers. Check in your environment and if you have such scenario, try to blacklist them. This will help reduce bandwidth usage and remove the bundle replication errors.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 11:51:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452094#M15880</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-02-06T11:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452095#M15881</link>
      <description>&lt;P&gt;This is a big giveaway: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;11-27-2018 20:12:16.688 +0100 WARN DistributedPeer - Peer: 
Unable to get server info from /services/server/info due to: No route to host
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Check your DNS settings. &lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 12:54:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452095#M15881</guid>
      <dc:creator>BainM</dc:creator>
      <dc:date>2019-02-06T12:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452096#M15882</link>
      <description>&lt;P&gt;Sorry for being late on this. I was able to solve this by copying the bundles from working indexer to non working indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452096#M15882</guid>
      <dc:creator>umeshagarwal008</dc:creator>
      <dc:date>2019-03-12T13:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452097#M15883</link>
      <description>&lt;P&gt;@umeshagarwal008 If your problem is resolved, please accept an answer to help future readers.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:23:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452097#M15883</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-03-12T14:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Distributed search peer not working as expected. There are multiple errors logs</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452098#M15884</link>
      <description>&lt;P&gt;Hi could you please explain what the file name of bundles that you move&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2019 06:12:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-Distributed-search-peer-not-working-as-expected-There-are/m-p/452098#M15884</guid>
      <dc:creator>ram254481493</dc:creator>
      <dc:date>2019-05-19T06:12:50Z</dc:date>
    </item>
  </channel>
</rss>

