<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: knowledge bundle replication error in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685266#M9995</link>
    <description>&lt;P&gt;Hello, by same error i mean that after changing the stanza config in distsearch.conf and restarting the service on the sh., there was the&amp;nbsp;&lt;SPAN&gt;Invalid key message on btool but with different value&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2024 08:48:38 GMT</pubDate>
    <dc:creator>yosoypako</dc:creator>
    <dc:date>2024-04-24T08:48:38Z</dc:date>
    <item>
      <title>knowledge bundle replication error</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685123#M9988</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hello.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;We are deploying a new search head in our splunk environment. We are using windows 2019 servers as platform. The nearch head is not working. We can see these errors on the indexer:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;WARN&lt;/SPAN&gt; &lt;SPAN class=""&gt;BundleDataProcessor&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;12404&lt;/SPAN&gt; &lt;SPAN class=""&gt;TcpChannelThread&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Failed&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;create&lt;/SPAN&gt; &lt;SPAN class=""&gt;file&lt;/SPAN&gt; &lt;SPAN class=""&gt;E:\Splunk\var\run\searchpeers\[search_head_hostname]-1713866571.e035b54cfcafb33b.tmp\apps\TA-microsoft-graph-security-add-on-for-splunk\bin\ta_microsoft_graph_security_add_on_for_splunk\aob_py2\cloudconnectlib\splunktacollectorlib\data_collection\ta_checkpoint_mng.py&lt;/SPAN&gt; &lt;SPAN class=""&gt;while&lt;/SPAN&gt; &lt;SPAN class=""&gt;untarring&lt;/SPAN&gt; &lt;SPAN class=""&gt;E:\Splunk\var\run\searchpeers\[search_head_hostname]-1713866571.bundle:&lt;/SPAN&gt; &lt;SPAN class=""&gt;The&lt;/SPAN&gt; &lt;SPAN class=""&gt;system&lt;/SPAN&gt; &lt;SPAN class=""&gt;cannot&lt;/SPAN&gt; &lt;SPAN class=""&gt;find&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;path&lt;/SPAN&gt; &lt;SPAN class=""&gt;specified.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;The file name (including the path) exceeds the limit of 260 characters on&amp;nbsp; windows OS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;How can we use this addon?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 12:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685123#M9988</guid>
      <dc:creator>yosoypako</dc:creator>
      <dc:date>2024-04-23T12:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle replication error</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685147#M9990</link>
      <description>&lt;P&gt;Have you carefully installed and deployed this add on within your Splunk deployment architecture&lt;/P&gt;&lt;P&gt;Follow the instructions &lt;A href="https://splunkbase.splunk.com/app/4564" target="_blank"&gt;https://splunkbase.splunk.com/app/4564&lt;/A&gt; - click on the link and look for where to install this add on section first.&lt;/P&gt;&lt;P&gt;You would typically be install this onto a heavy forwarder if you are using one and set the inputs up, this would forward the data to the indexers and data will be parsed.&lt;/P&gt;&lt;P&gt;The add is required on the Search Heads for parsing (Knowledge Objects) so needs to be installed there, into the correct path.&lt;/P&gt;&lt;P&gt;So Install everythings as required, configure it and then look at the logs.&lt;/P&gt;&lt;P&gt;If you have already configured as required then this log message indicates something else.&lt;/P&gt;&lt;P&gt;It states "The system cannot find the path specified"&lt;/P&gt;&lt;P&gt;Have you installed it correctly?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 13:49:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685147#M9990</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-04-23T13:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle replication error</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685154#M9991</link>
      <description>&lt;P&gt;Your first error is deploying Splunk on Windows.&amp;nbsp;&amp;nbsp; See &lt;A href="https://community.splunk.com/t5/Getting-Data-In/What-are-the-pain-points-with-deploying-your-Splunk-architecture/m-p/650011" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/What-are-the-pain-points-with-deploying-your-Splunk-architecture/m-p/650011&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Please elaborate on "the search head is not working".&amp;nbsp; What about it is not working?&amp;nbsp; An error on an indexer does not necessarily mean there's a problem with the SH.&lt;/P&gt;&lt;P&gt;One workaround is to rename the TA so it resides in a directory with a shorter name (by at least 8 characters).&amp;nbsp; Of course, you will have to maintain that forever.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685154#M9991</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-23T14:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle replication error</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685157#M9992</link>
      <description>&lt;P&gt;Hello, thanks for your help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Until now were using a single deployment of splunk (indexer, search head and data inputs) on the same box.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we have just started to split the roles by deploying a new search head.&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the search is not working I meant that the service is up and running, we can log on it but the searches are not running. We got this message:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Unable to distribute to peer named [indexer_splunk_instancename] at uri https://[indexer_ip]:8089 because replication was unsuccessful. ReplicationStatus: Failed - Failure info: failed_because_BUNDLE_DATA_TRANSMIT_FAILURE. Verify connectivity to the search peer, that the search peer is up, and that an adequate level of system resources are available.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On the indexer, on splunkd.log we got these messages:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;File length is greater than 260, File creation may fail.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After reading the doc, I saw the&amp;nbsp; app is supported on the indexers but it is not required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If we move this application to one heavy forwarder. It will not be included on the replication bundle between SH and Indexer?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685157#M9992</guid>
      <dc:creator>yosoypako</dc:creator>
      <dc:date>2024-04-23T14:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle replication error</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685165#M9993</link>
      <description>&lt;P&gt;If the app is installed on the SH, it will be replicated to the indexer UNLESS it is excluded from the bundle.&amp;nbsp; To exclude files from the bundle, add entries to the [replicationDenyList] stanza in distsearch.conf and restart the SH.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[replicationDenyList]
MSbin = E:\Splunk\etc\apps\TA-microsoft-graph-security-add-on-for-splunk\bin\*&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 23 Apr 2024 15:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685165#M9993</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-23T15:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle replication error</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685264#M9994</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;I have tried different combination of&amp;nbsp;replicationDenyList stanza definition, in all cases it did not work.&lt;/P&gt;&lt;P&gt;with quotes, "apps\TA-microsoft-graph-security-add-on-for-splunk\bin\...", without quotes&amp;nbsp;apps\TA-microsoft-graph-security-add-on-for-splunk\bin\... , with *&amp;nbsp;"apps\TA-microsoft-graph-security-add-on-for-splunk\bin\*", with full path&amp;nbsp;D:\Splunk Search Head\etc\apps\TA-microsoft-graph-security-add-on-for-splunk\bin\*, and combinations of them. But nothing, I always got the error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;Invalid key in stanza [replicationDenyList] in D:\Splunk Search Head\etc\system\local\distsearch.conf, line 29: MSbin (value: apps\TA-microsoft-graph-security-add-on-for-splunk\bin\*).&lt;/P&gt;&lt;P&gt;Do you have a working example of this stanza?&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 08:33:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685264#M9994</guid>
      <dc:creator>yosoypako</dc:creator>
      <dc:date>2024-04-24T08:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle replication error</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685266#M9995</link>
      <description>&lt;P&gt;Hello, by same error i mean that after changing the stanza config in distsearch.conf and restarting the service on the sh., there was the&amp;nbsp;&lt;SPAN&gt;Invalid key message on btool but with different value&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 08:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685266#M9995</guid>
      <dc:creator>yosoypako</dc:creator>
      <dc:date>2024-04-24T08:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: knowledge bundle replication error</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685299#M9997</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now it is working.&lt;/P&gt;&lt;P&gt;This made the trick:&lt;/P&gt;&lt;P&gt;[replicationDenylist]&lt;BR /&gt;ms_graph = ...TA-microsoft-graph-security-add-on-for-splunk[/\\]bin[/\\]...&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2024 11:35:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/knowledge-bundle-replication-error/m-p/685299#M9997</guid>
      <dc:creator>yosoypako</dc:creator>
      <dc:date>2024-04-24T11:35:46Z</dc:date>
    </item>
  </channel>
</rss>

