<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Deployments Server error on Linux Search Head in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557827#M5086</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Answer#1: We have only recently setup the Linux for Splunk. So deployment servers are still Windows. Getting ports for Universal Forwarders opened is a pain...hopefully we would switch to Linux someday...&lt;/P&gt;&lt;P&gt;Answer#2:We have some reports that need data from the deployment server directly. Now that you have mentioned it, I might use Summary Indexing on the Deployment Servers to send the data over and disable them as search peeers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But until that is done, my main concern is------&lt;/P&gt;&lt;P&gt;Can we use a setting/config anywhere on the SH that will stop replication of bundle only on these two boxes while the bundle continues to replicate on other Linux servers?&lt;/P&gt;&lt;P&gt;Thanks for your help....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jun 2021 14:41:31 GMT</pubDate>
    <dc:creator>neeravmathur</dc:creator>
    <dc:date>2021-06-30T14:41:31Z</dc:date>
    <item>
      <title>Windows Deployments Server error on Linux Search Head</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557775#M5077</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;We use 3 Search Heads (cluster-linux boxes) with 2 Deployment boxes (1-PROD, 1-QA, Win 2012R2-32GB RAM Each) as searchpeer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the other servers listed under distsearch.conf of SH are linux boxes. We constantly get messages on our search head -&lt;/P&gt;&lt;P&gt;""Unable to distribute to peer named XXXXXXXX at uri=XXXXXXXXXX:8089 using the uri-scheme=https because peer has status=Down. Verify uri-scheme, connectivity to the search peer, that the search peer is up, and that an adequate level of system resources are available. See the Troubleshooting Manual for more information.""&lt;/P&gt;&lt;P&gt;AND&lt;/P&gt;&lt;P&gt;"Problem replicating config (bundle) to search peer 'XXXXXXX', Upload bundle="/SPLUNK/splunk/var/run/54C7554E-300C-462E-A82D-6AE880CB89BF-1624948028.bundle" to peer name=XXXXXXX uri=&lt;A href="https://XXXXXXX:8089" target="_blank"&gt;https://XXXXXXX:8089&lt;/A&gt; failed; http_status=400 http_description="Failed to untar the bundle="D:\Splunk\var\run\searchpeers\54C7554E-300C-462E-A82D-6AE880CB89BF-1624948028.bundle". This could be due Search Head attempting to upload the same bundle again after a timeout. Check for sendRcvTimeout message in splund.log, consider increasing it."."&lt;/P&gt;&lt;P&gt;This happens only with the 2 Win-Deployment boxes. Linux boxes do not throw such alerts ever...&lt;/P&gt;&lt;P&gt;My question is are both issues interrelated?&lt;BR /&gt;The state of these 2 servers often go from UP to DOWN on the Search peer UI on the Search Head.&lt;BR /&gt;Troubleshooting details below which we tried but did not work-&lt;BR /&gt;1. We have tried removing them and adding them again from the GUI and the distsearch.conf and authenticating them again.&lt;BR /&gt;2. In distsearch.conf on SH-&lt;BR /&gt;[replicationSettings]&lt;BR /&gt;sendRcvTimeout = 240&lt;BR /&gt;3.Size of SH bundle is about 125MB which is not huge....&lt;/P&gt;&lt;P&gt;Not sure what needs to be done here. Any help would be appreciated........&lt;/P&gt;&lt;P&gt;Hoping for a quick fix on this.&lt;BR /&gt;Thanks for your help.....&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 09:42:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557775#M5077</guid>
      <dc:creator>neeravmathur</dc:creator>
      <dc:date>2021-06-30T09:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Deployments Server error on Linux Search Head</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557781#M5078</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224707"&gt;@neeravmathur&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;only for information: what do you mean with&amp;nbsp; "&lt;SPAN&gt;Deployment boxes (1-PROD, 1-QA, Win 2012R2-32GB RAM Each) as searchpeer."?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;are you speaking of Indexers or Deployer or Deployment Server?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you're meaning "Deployer", in other words the Splunk component that manages the Search Head Cluster, it's better to have the same OS than the Search Heads.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you better describe your architecture, using the Splunk roles: Indexer, Search Head, Master Node, Deployer, Deployment Server?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyway, my hint is to use Windows servers&amp;nbsp;at most for tests and use always Linux servers for production environments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 10:55:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557781#M5078</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-30T10:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Deployments Server error on Linux Search Head</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557784#M5079</link>
      <description>&lt;P&gt;Apologies...should have been more clear.....&lt;/P&gt;&lt;P&gt;So IN PROD we have 3 SH (clustered), 2 Indexers (non clustered), 1 Deployer and 1 Deployment Server&amp;nbsp;&lt;/P&gt;&lt;P&gt;and IN QA we have 1 SH, 2 Indexers, 1 Deployment Server&lt;/P&gt;&lt;P&gt;Now, both the deployment Servers are Windows (having 32 GB memory) and both servers are configured in Search Head's distsearch and act as Search Peer.&lt;/P&gt;&lt;P&gt;All the other components like SH,Indexer,Deployer are Linux and work just fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the Search heads I always see the mentioned errors/messages.&lt;/P&gt;&lt;P&gt;Is there anything that I am missing or can be configured so that these sync errors do not come up...They are huge inconivence....&lt;/P&gt;&lt;P&gt;I agree that Linux Servers are much better but since these are deployment servers so opening ports again would be a big challenge for us.&lt;/P&gt;&lt;P&gt;Hope this helps...Thanks for your prompt response....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 11:11:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557784#M5079</guid>
      <dc:creator>neeravmathur</dc:creator>
      <dc:date>2021-06-30T11:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Deployments Server error on Linux Search Head</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557799#M5080</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224707"&gt;@neeravmathur&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I try to summarize:&lt;/P&gt;&lt;P&gt;in production you have:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;3 SHs Linux clustered,&lt;/LI&gt;&lt;LI&gt;1 Deployer Linux that manages the clustered SHs,&lt;/LI&gt;&lt;LI&gt;2 Indexers Linux not clustered,&lt;/LI&gt;&lt;LI&gt;1 Deployment Server Windows,&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In QA you have:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1 SH, Linux,&lt;/LI&gt;&lt;LI&gt;2 Indexers Linux not clustered,&lt;/LI&gt;&lt;LI&gt;1 Deployment Server Windows,&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;All the Splunk servers send their own log to the Indexers.&lt;/P&gt;&lt;P&gt;My first question is obviously: why do you use Windows Deployment Servers when all the other servers are Linux? I'd avoid it!&lt;/P&gt;&lt;P&gt;Second question: why do You use Deployment Servers as Search Peer on Search Head? it isn't an Indexer and it's a best practice that all the Splunk servers (also Deployment Servers) send log to Indexers.&lt;/P&gt;&lt;P&gt;Now I understand the message you have.&lt;/P&gt;&lt;P&gt;A correct architecture is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SH Cluster use both Indexers as Search Peers,&lt;/LI&gt;&lt;LI&gt;All the servers are Linux,&lt;/LI&gt;&lt;LI&gt;All the servers send their own logs to Indexers,&lt;/LI&gt;&lt;LI&gt;this rules must be separately applied to Proiduction and QA Environments.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 12:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557799#M5080</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-06-30T12:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Deployments Server error on Linux Search Head</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557827#M5086</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Answer#1: We have only recently setup the Linux for Splunk. So deployment servers are still Windows. Getting ports for Universal Forwarders opened is a pain...hopefully we would switch to Linux someday...&lt;/P&gt;&lt;P&gt;Answer#2:We have some reports that need data from the deployment server directly. Now that you have mentioned it, I might use Summary Indexing on the Deployment Servers to send the data over and disable them as search peeers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But until that is done, my main concern is------&lt;/P&gt;&lt;P&gt;Can we use a setting/config anywhere on the SH that will stop replication of bundle only on these two boxes while the bundle continues to replicate on other Linux servers?&lt;/P&gt;&lt;P&gt;Thanks for your help....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 14:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557827#M5086</guid>
      <dc:creator>neeravmathur</dc:creator>
      <dc:date>2021-06-30T14:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Deployments Server error on Linux Search Head</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557983#M5087</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224707"&gt;@neeravmathur&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, I don't like to use Deployment Server for other scope than deployment.&lt;/P&gt;&lt;P&gt;In addition you cannot use that Summary Index on the Search Heads.&lt;/P&gt;&lt;P&gt;You could send DS data to indexers and then create Summary Index on The Search Heads or the Indexers.&lt;/P&gt;&lt;P&gt;As I said it's a best practice that all the Splunk servers send their data to the Indexers.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 06:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/557983#M5087</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-01T06:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Deployments Server error on Linux Search Head</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/558015#M5088</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thanks for your suggestion...will try it out...thanks again for your time and help.....&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 11:06:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/558015#M5088</guid>
      <dc:creator>neeravmathur</dc:creator>
      <dc:date>2021-07-01T11:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Deployments Server error on Linux Search Head</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/558016#M5089</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224707"&gt;@neeravmathur&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, tell me if I can help you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: please accept the answer for the other people of Community, Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 11:19:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Windows-Deployments-Server-error-on-Linux-Search-Head/m-p/558016#M5089</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-01T11:19:40Z</dc:date>
    </item>
  </channel>
</rss>

