<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to resolve &amp;quot;Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response code 400 HTTP/1.1 400 Unparsable URI-encoded request data.&amp;quot;? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347123#M63760</link>
    <description>&lt;P&gt;I would log into the search head, remove the indexer as a search peer, then re-add it again. Sounds like something has become confused on the backend.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Mar 2017 05:32:56 GMT</pubDate>
    <dc:creator>mrgibbon</dc:creator>
    <dc:date>2017-03-15T05:32:56Z</dc:date>
    <item>
      <title>How to resolve "Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response code 400 HTTP/1.1 400 Unparsable URI-encoded request data."?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347121#M63758</link>
      <description>&lt;P&gt;Have 1 indexer and 1 search head. Separate VM's. When trying to view indexed data from search head UI we receive the error "Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response code 400 HTTP/1.1 400 Unparsable URI-encoded request data.", and get "No results found" in the search window. We know there is indexed data because we can search it using the UI on the indexer itself.&lt;/P&gt;

&lt;P&gt;Search Head (SH) splunkd.log shows: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR DistributedBundleReplicationManager - got non-200 response from peer. uri=https://xxxxx.yyyy.com:8089, reply="HTTP/1.1 400 Unparsable URI-encoded request data" response_code=400
ERROR DistributedBundleReplicationManager - Unable to upload bundle to peer named  with uri=https://xxxxx.yyyy.com:8089
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Indexer splunkd_access.log shows the 400 error:   &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;- - [13/Mar/2017:14:31:59.835 -0400] "POST /services/receivers/bundle/ HTTP/1.0" 400 153 - - - 0ms
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;There are no ERRORS in the splunkd.log on the Indexer.&lt;BR /&gt;
There is physical connectivity to the host/port from the SH to the Indexer (we would see the log entry in the indexer if there was no connectivity).&lt;/P&gt;

&lt;P&gt;What is going on, and how can we correct? &lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 18:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347121#M63758</guid>
      <dc:creator>ksoucy</dc:creator>
      <dc:date>2017-03-13T18:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response code 400 HTTP/1.1 400 Unparsable URI-encoded request data."?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347122#M63759</link>
      <description>&lt;P&gt;Correction: (we would see the log entry in the indexer if there was no connectivity), should state: (we would NOT see the log entry in the indexer if there was no connectivity)&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 15:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347122#M63759</guid>
      <dc:creator>ksoucy</dc:creator>
      <dc:date>2017-03-14T15:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response code 400 HTTP/1.1 400 Unparsable URI-encoded request data."?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347123#M63760</link>
      <description>&lt;P&gt;I would log into the search head, remove the indexer as a search peer, then re-add it again. Sounds like something has become confused on the backend.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2017 05:32:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347123#M63760</guid>
      <dc:creator>mrgibbon</dc:creator>
      <dc:date>2017-03-15T05:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response code 400 HTTP/1.1 400 Unparsable URI-encoded request data."?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347124#M63761</link>
      <description>&lt;P&gt;Here was resolution - we think. We did not have the Search Head configured as a License Slave, so it was not working with the same license that was installed on the Indexer (which we have designated as the license master). Once we set the search head to a license slave, the bundle distribution worked and we were able to search data in the index(es). Seems a more accurate error could be produced in these situations (without having to set any logging to the Debug level).&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 15:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347124#M63761</guid>
      <dc:creator>ksoucy</dc:creator>
      <dc:date>2017-03-17T15:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response code 400 HTTP/1.1 400 Unparsable URI-encoded request data."?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347125#M63762</link>
      <description>&lt;P&gt;Here was resolution - we think. We did not have the Search Head configured as a License Slave, so it was not working with the same license that was installed on the Indexer (which we have designated as the license master). Once we set the search head to a license slave, the bundle distribution worked and we were able to search data in the index(es). Seems a more accurate error could be produced in these situations (without having to set any logging to the Debug level).&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 15:15:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347125#M63762</guid>
      <dc:creator>ksoucy</dc:creator>
      <dc:date>2017-03-17T15:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response code 400 HTTP/1.1 400 Unparsable URI-encoded request data."?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347126#M63763</link>
      <description>&lt;P&gt;If the problem is resolved, please accept an answer.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 15:23:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347126#M63763</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-03-17T15:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response code 400 HTTP/1.1 400 Unparsable URI-encoded request data."?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347127#M63764</link>
      <description>&lt;P&gt;This can happen, when both systems have diverting License-Master/Licenses.&lt;/P&gt;

&lt;P&gt;You should set the licensemaster to the same master_uri/same license pool.&lt;/P&gt;

&lt;P&gt;On the License-Slave:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk edit licenser-localslave -master_uri &lt;A href="https://&amp;lt;license-master&amp;gt;:8089" target="test_blank"&gt;https://&amp;lt;license-master&amp;gt;:8089&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or via server.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[license]
master_uri = &lt;A href="https://&amp;lt;licensemaster&amp;gt;:8089" target="test_blank"&gt;https://&amp;lt;licensemaster&amp;gt;:8089&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However HTTP 400 Response is a very ambiguous message. Splunk should implement a proper Error-Message for this case.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 15:30:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/347127#M63764</guid>
      <dc:creator>effem</dc:creator>
      <dc:date>2020-02-14T15:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "Problem replicating config (bundle) to search peer 'xxxxx.yyyy.com:8089', got http response cod</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/579117#M102246</link>
      <description>&lt;P&gt;Even though the License configurations are correct, you could have a bad route or firewall block.&amp;nbsp; To test for this, you can do this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[splunk@MyDeploymenServer]$ /usr/bin/echo &amp;gt; /dev/tcp/License.Master.IP.Here/8089 &amp;amp;&amp;amp; /usr/bin/echo "master is reachable" || /usr/bin/echo "master is unreachable: $(/usr/bin/date)"
-bash: connect: No route to host 
-bash: /dev/tcp/License.Master.IP.Here/8089: No route to host master is unreachable: Wed Dec 22 11:18:19 EST 2021&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 22 Dec 2021 16:22:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-quot-Problem-replicating-config-bundle-to-search/m-p/579117#M102246</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2021-12-22T16:22:18Z</dc:date>
    </item>
  </channel>
</rss>

