<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How should I set the con_replication_max_pull_count value for search head cluster members to pull configuration changes from the captain? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-should-I-set-the-con-replication-max-pull-count-value-for/m-p/222809#M8342</link>
    <description>&lt;P&gt;replication_factor = 1&lt;/P&gt;

&lt;P&gt;but that is only for replication of search artifacts&lt;/P&gt;

&lt;P&gt;The WARN message is referring to configuration changes, like knowledge objects changing by users via the UI.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Feb 2016 18:51:32 GMT</pubDate>
    <dc:creator>ben_leung</dc:creator>
    <dc:date>2016-02-26T18:51:32Z</dc:date>
    <item>
      <title>How should I set the con_replication_max_pull_count value for search head cluster members to pull configuration changes from the captain?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-should-I-set-the-con-replication-max-pull-count-value-for/m-p/222807#M8340</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;WARN  ConfMetrics - single_action=PULL_FROM took wallclock_ms=4610! Consider a lower value of conf_replication_max_pull_count in server.conf on all members
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What should I base the value on for conf_replication_max_pull_count? The warning is telling me that the cluster nodes are taking too long to pull configuration changes from the captain. Is my understanding correct?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;conf_replication_max_pull_count = &amp;lt;int&amp;gt;
* Controls the maximum number of configuration changes a member will
  replicate from the captain at one time.
* A value of 0 disables any size limits.
* Defaults to 1000.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:56:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-should-I-set-the-con-replication-max-pull-count-value-for/m-p/222807#M8340</guid>
      <dc:creator>ben_leung</dc:creator>
      <dc:date>2020-09-29T08:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: How should I set the con_replication_max_pull_count value for search head cluster members to pull configuration changes from the captain?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-should-I-set-the-con-replication-max-pull-count-value-for/m-p/222808#M8341</link>
      <description>&lt;P&gt;What is your cluster's ref factor?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 18:39:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-should-I-set-the-con-replication-max-pull-count-value-for/m-p/222808#M8341</guid>
      <dc:creator>splunkIT</dc:creator>
      <dc:date>2016-02-26T18:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: How should I set the con_replication_max_pull_count value for search head cluster members to pull configuration changes from the captain?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-should-I-set-the-con-replication-max-pull-count-value-for/m-p/222809#M8342</link>
      <description>&lt;P&gt;replication_factor = 1&lt;/P&gt;

&lt;P&gt;but that is only for replication of search artifacts&lt;/P&gt;

&lt;P&gt;The WARN message is referring to configuration changes, like knowledge objects changing by users via the UI.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2016 18:51:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-should-I-set-the-con-replication-max-pull-count-value-for/m-p/222809#M8342</guid>
      <dc:creator>ben_leung</dc:creator>
      <dc:date>2016-02-26T18:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: How should I set the con_replication_max_pull_count value for search head cluster members to pull configuration changes from the captain?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-should-I-set-the-con-replication-max-pull-count-value-for/m-p/222810#M8343</link>
      <description>&lt;P&gt;Unless advised by Support, it's probably not a good idea to modify the  conf_replication_max_pull_count setting.&lt;/P&gt;

&lt;P&gt;The WARN itself is not necessarily a problem, unless it corresponds to slow UI response times and/or general system problems. &lt;/P&gt;

&lt;P&gt;In general, note that this message is based on wallclock time. That means any performance problem on the system – e.g. memory pressure or contention for CPU – can cause this WARN. It isn't always a problem with the configuration replication workload itself. &lt;/P&gt;

&lt;P&gt;If the WARN message corresponds to slow UI response times and/or general system problems, then please contact Support and provide the following artifacts for further analysis: &lt;/P&gt;

&lt;P&gt;1.) Collect new diags from captain and from at least one of the member nodes &lt;BR /&gt;
2.) On each of the search heads, please take of backup of the latest bundle file under var/run/splunk/snapshot to a temporary directory, and provide them as well&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:10:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-should-I-set-the-con-replication-max-pull-count-value-for/m-p/222810#M8343</guid>
      <dc:creator>splunkIT</dc:creator>
      <dc:date>2020-09-29T09:10:26Z</dc:date>
    </item>
  </channel>
</rss>

