<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bundle replication fails with: response_code=204 in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Bundle-replication-fails-with-response-code-204/m-p/175356#M6525</link>
    <description>&lt;P&gt;The search-head fails to retrieve results from some/all search-peers and emits messages like so on the UI: &lt;/P&gt;

&lt;P&gt;"Problem replicating config (bundle) to search peer 'peer_host:8089', got http response code 204 HTTP/1.1 204 No Content"&lt;/P&gt;

&lt;P&gt;The search-head splunkd.log shows: &lt;/P&gt;

&lt;P&gt;ERROR DistributedBundleReplicationManager - got non-200 response from peer.uri=&lt;A href="https://peer_host:8089"&gt;https://peer_host:8089&lt;/A&gt;, reply="HTTP/1.1 204 No Content" response_code=204&lt;/P&gt;</description>
    <pubDate>Thu, 07 Aug 2014 21:29:26 GMT</pubDate>
    <dc:creator>drrushi_splunk</dc:creator>
    <dc:date>2014-08-07T21:29:26Z</dc:date>
    <item>
      <title>Bundle replication fails with: response_code=204</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Bundle-replication-fails-with-response-code-204/m-p/175356#M6525</link>
      <description>&lt;P&gt;The search-head fails to retrieve results from some/all search-peers and emits messages like so on the UI: &lt;/P&gt;

&lt;P&gt;"Problem replicating config (bundle) to search peer 'peer_host:8089', got http response code 204 HTTP/1.1 204 No Content"&lt;/P&gt;

&lt;P&gt;The search-head splunkd.log shows: &lt;/P&gt;

&lt;P&gt;ERROR DistributedBundleReplicationManager - got non-200 response from peer.uri=&lt;A href="https://peer_host:8089"&gt;https://peer_host:8089&lt;/A&gt;, reply="HTTP/1.1 204 No Content" response_code=204&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2014 21:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Bundle-replication-fails-with-response-code-204/m-p/175356#M6525</guid>
      <dc:creator>drrushi_splunk</dc:creator>
      <dc:date>2014-08-07T21:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Bundle replication fails with: response_code=204</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Bundle-replication-fails-with-response-code-204/m-p/175357#M6526</link>
      <description>&lt;P&gt;First check the peer's splunkd.log for any messages during the same time as the search-head's DistributedBundleReplicationManager error. &lt;/P&gt;

&lt;P&gt;If you do find in the peer's splunkd.log messages such as: &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;ERROR DistBundleRestHandler - File users/xxx/yyy/local/props.conf in knowledge bundle is either not in white list or else excluded by black list. Bundle /opt/splunk/var/run/searchpeers/&lt;BUNDLE_NAME&gt; will be removed&lt;/BUNDLE_NAME&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;...then this means that there must be on the peer a rouge 'distsearch.conf' which does't not explicitly whitelist or blacklist any bundle files ... as a result by default the peer simply rejects the bundle. &lt;/P&gt;

&lt;P&gt;To workaround this please remove any distsearch.conf (from system/local OR etc/apps/appname/local) on the peers and restart Splunk.  &lt;/P&gt;

&lt;P&gt;In version 6.1 a new functionality was added to the peer which allows peers to blacklist/whitelist bundle contents based on locally defined rules (via local distsearch.conf). &lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2014 21:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Bundle-replication-fails-with-response-code-204/m-p/175357#M6526</guid>
      <dc:creator>drrushi_splunk</dc:creator>
      <dc:date>2014-08-07T21:35:10Z</dc:date>
    </item>
  </channel>
</rss>

