<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forced bundle replication failed. Reverting to old behavior - using most recent bundles on all in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Forced-bundle-replication-failed-Reverting-to-old-behavior-using/m-p/567014#M24871</link>
    <description>&lt;P&gt;Try cycling the index master, then a rolling restart of the indexer cluster. Once the cluster is back up try to re-validate the new bundle via the master.&lt;/P&gt;&lt;P&gt;If that doesn't work, make a small change in your bundle somewhere like a add/modify a readme text file, etc.&lt;BR /&gt;That's enough to cause the master to see it as a new bundle and re-validate.&lt;/P&gt;&lt;P&gt;Using the GUI on the master is actually the easiest/best way to do the restart, cycling, and bundle validation/push, in my opinion. Just fyi.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2021 19:22:48 GMT</pubDate>
    <dc:creator>codebuilder</dc:creator>
    <dc:date>2021-09-14T19:22:48Z</dc:date>
    <item>
      <title>Forced bundle replication failed. Reverting to old behavior - using most recent bundles on all</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Forced-bundle-replication-failed-Reverting-to-old-behavior-using/m-p/566958#M24866</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello everyone. I'm getting&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Forced bundle replication failed. Reverting to old behavior - using most recent bundles on all&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;on a search head, and I'm not sure how to fix this. I excluded heavy files from the bundle, also restarted the search head, but nothing changes. Where should I dig? I wasn't able to find this error message in Splunk documentation and on the internet. The closest topic on Splunk answers was related to search head clustering, but since I wasn't setting up SH clustering, I guess it's not applicable.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Additional info. Before the issue occurred, I've noticed that disk usage on indexers went to 100%. I solved it by deleting data from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;/opt/splunk/var/run/searchpeers&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(except the latest files).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My environment: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- 4 indexer VMs.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- 2 search head VMs (not clustered, just testing Splunk 7 and Splunk 8 in parallel). 4 indexers are connected as distributed search peers to each of those search heads.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- No deployment server in use.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sometimes network connection is not good between indexers and search head, so maybe it contributes somehow.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any suggestions and ideas appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 09:45:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Forced-bundle-replication-failed-Reverting-to-old-behavior-using/m-p/566958#M24866</guid>
      <dc:creator>vzabawski</dc:creator>
      <dc:date>2021-09-14T09:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forced bundle replication failed. Reverting to old behavior - using most recent bundles on all</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Forced-bundle-replication-failed-Reverting-to-old-behavior-using/m-p/567014#M24871</link>
      <description>&lt;P&gt;Try cycling the index master, then a rolling restart of the indexer cluster. Once the cluster is back up try to re-validate the new bundle via the master.&lt;/P&gt;&lt;P&gt;If that doesn't work, make a small change in your bundle somewhere like a add/modify a readme text file, etc.&lt;BR /&gt;That's enough to cause the master to see it as a new bundle and re-validate.&lt;/P&gt;&lt;P&gt;Using the GUI on the master is actually the easiest/best way to do the restart, cycling, and bundle validation/push, in my opinion. Just fyi.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 19:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Forced-bundle-replication-failed-Reverting-to-old-behavior-using/m-p/567014#M24871</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2021-09-14T19:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Forced bundle replication failed. Reverting to old behavior - using most recent bundles on all</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Forced-bundle-replication-failed-Reverting-to-old-behavior-using/m-p/567064#M24877</link>
      <description>&lt;P&gt;Thanks for your reply. What should I do if it isn't an indexer cluster? Those indexers are standalone, so there's no replication going on, and no indexer master is present.&lt;/P&gt;&lt;P&gt;Anyway, I think restarting indexers might be a good idea, so I'll try it.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 07:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Forced-bundle-replication-failed-Reverting-to-old-behavior-using/m-p/567064#M24877</guid>
      <dc:creator>vzabawski</dc:creator>
      <dc:date>2021-09-15T07:23:55Z</dc:date>
    </item>
  </channel>
</rss>

