<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bundle Replication: Problem replicating config (bundle) to search peer in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Bundle-Replication-Problem-replicating-config-bundle-to-search/m-p/471673#M16444</link>
    <description>&lt;P&gt;What version of Splunk are you running? There have been some specific versions with bugs related to this.&lt;/P&gt;

&lt;P&gt;Have you tried manually cleaning up that folder?&lt;/P&gt;

&lt;P&gt;Have you tried shrinking your bundle? Do you have some very large lookups in there or so? Do you really need those on the indexers (you do if you want to use them in automatic lookups)? If not, blacklist them. Also, avoid including apps with big binary components in them, that are of no use on SH/IDX layers (e.g. scripts/binaries used for data input on a HF or so).&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2019 08:19:15 GMT</pubDate>
    <dc:creator>FrankVl</dc:creator>
    <dc:date>2019-10-30T08:19:15Z</dc:date>
    <item>
      <title>Bundle Replication: Problem replicating config (bundle) to search peer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Bundle-Replication-Problem-replicating-config-bundle-to-search/m-p/471672#M16443</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I am very frequently getting below warning on UI:&lt;BR /&gt;
"Bundle Replication: Problem replicating config (bundle) to search peer 'servername:8089', HTTP response code 413 (HTTP/1.1 413 Content-Length of 3174266880 too large (maximum is 3145728000)). Content-Length of 3174266880 too large (maximum is 3145728000) (Unknown write error)"&lt;/P&gt;

&lt;P&gt;With a bit of finding and analysis, i have increased max_content_length under [http server] in $SPLUNK_HOME/etc/system/default/server.conf from 2GB to 8GB.&lt;BR /&gt;
Also *.bundle.info files were getting coagulated at $SPLUNK_HOME/var/run/, because the size of bundle was 3.01GB and what i have set in distsearch.conf (maxbundlesize) is 3gb, so i have increased that size to 4gb.&lt;/P&gt;

&lt;P&gt;But still my splunk directory is wholly consumed, 100% utilization.&lt;/P&gt;

&lt;P&gt;Kindly suggest if you have any comments on this please.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:46:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Bundle-Replication-Problem-replicating-config-bundle-to-search/m-p/471672#M16443</guid>
      <dc:creator>sarvesh_11</dc:creator>
      <dc:date>2020-09-30T02:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Bundle Replication: Problem replicating config (bundle) to search peer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Bundle-Replication-Problem-replicating-config-bundle-to-search/m-p/471673#M16444</link>
      <description>&lt;P&gt;What version of Splunk are you running? There have been some specific versions with bugs related to this.&lt;/P&gt;

&lt;P&gt;Have you tried manually cleaning up that folder?&lt;/P&gt;

&lt;P&gt;Have you tried shrinking your bundle? Do you have some very large lookups in there or so? Do you really need those on the indexers (you do if you want to use them in automatic lookups)? If not, blacklist them. Also, avoid including apps with big binary components in them, that are of no use on SH/IDX layers (e.g. scripts/binaries used for data input on a HF or so).&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 08:19:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Bundle-Replication-Problem-replicating-config-bundle-to-search/m-p/471673#M16444</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-10-30T08:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: Bundle Replication: Problem replicating config (bundle) to search peer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Bundle-Replication-Problem-replicating-config-bundle-to-search/m-p/471674#M16445</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/87518"&gt;@FrankVl&lt;/a&gt;  thanks for dropping by,&lt;BR /&gt;
This is Splunk Enterprise 6.6.3.&lt;/P&gt;

&lt;P&gt;Our search head is Standalone, on-prem, and indexer is on cloud.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;I am just wondering does max_content_length is set to 3145728000 on Indexer?&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I am about to reduce the bundle size, but if i have set &lt;BR /&gt;
max_content_lenght=8Gb in server.conf &amp;amp;&lt;BR /&gt;
maxbundlesize = 4gb in distsearch.conf.&lt;/P&gt;

&lt;P&gt;Then ideally these bundles should parse from Search Head to Indexer. And should not give error as maximum is 3145728000.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Bundle-Replication-Problem-replicating-config-bundle-to-search/m-p/471674#M16445</guid>
      <dc:creator>sarvesh_11</dc:creator>
      <dc:date>2020-09-30T02:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Bundle Replication: Problem replicating config (bundle) to search peer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Bundle-Replication-Problem-replicating-config-bundle-to-search/m-p/471675#M16446</link>
      <description>&lt;P&gt;Not sure if I get your question correct, but yes, I do believe you need to set that &lt;CODE&gt;max_content_lenght&lt;/CODE&gt; on the indexers. It is the indexers that are rejecting the oversized bundle coming from the Search Heads.&lt;/P&gt;

&lt;P&gt;You might also want to double check using btool, that those settings are taken correctly.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 08:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Bundle-Replication-Problem-replicating-config-bundle-to-search/m-p/471675#M16446</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-10-30T08:59:28Z</dc:date>
    </item>
  </channel>
</rss>

