<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search head cluster error?? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/search-head-cluster-error/m-p/322009#M2972</link>
    <description>&lt;P&gt;some how i figured out the problem. the issue was with the kvstore port (8191). firewall rule was blocking it. the captain was unable to connect to other nodes and write to kvstore&lt;/P&gt;</description>
    <pubDate>Mon, 17 Apr 2017 14:06:17 GMT</pubDate>
    <dc:creator>AzmathShaik</dc:creator>
    <dc:date>2017-04-17T14:06:17Z</dc:date>
    <item>
      <title>search head cluster error??</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/search-head-cluster-error/m-p/322007#M2970</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;i am deploy new search head cluster, the deployment went successful but when i check the splunkd.log i fount one strange warning&lt;BR /&gt;
&lt;STRONG&gt;04-08-2017 03:46:21.294 +0000 WARN ConfReplicationBookmark - serializeToJson: tried to serialize an empty bookmark&lt;BR /&gt;
04-08-2017 03:46:21.294 +0000 WARN  SHCHouseKeepingThread - writeSHCStateToStateStore: failed to serialize the bookmark&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;i am curious to know about this. what does it exactly means and is this a harmful warning?&lt;BR /&gt;
do i face issues with this warning?&lt;/P&gt;

&lt;P&gt;can some help me ?&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sat, 08 Apr 2017 03:56:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/search-head-cluster-error/m-p/322007#M2970</guid>
      <dc:creator>AzmathShaik</dc:creator>
      <dc:date>2017-04-08T03:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: search head cluster error??</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/search-head-cluster-error/m-p/322008#M2971</link>
      <description>&lt;P&gt;It indicates this Splunk instance could not understand SHC node status. I suspect you cannot see SHC status (splunk show shcsluter-status) in this node when the message was generated. I also suspect your conf replication is failing. &lt;/P&gt;

&lt;P&gt;In that case, you might need to run destructive resync command to resolve the issue.  You should make a backup of etc directory before running the command. &lt;/P&gt;

&lt;P&gt;You said a new search head cluster. Are those Search head instances new ?  If so, do you have three or more search heads?  Please make sure you meet requirement to deploy a new SHC. &lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2017 01:14:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/search-head-cluster-error/m-p/322008#M2971</guid>
      <dc:creator>Masa</dc:creator>
      <dc:date>2017-04-15T01:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: search head cluster error??</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/search-head-cluster-error/m-p/322009#M2972</link>
      <description>&lt;P&gt;some how i figured out the problem. the issue was with the kvstore port (8191). firewall rule was blocking it. the captain was unable to connect to other nodes and write to kvstore&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 14:06:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/search-head-cluster-error/m-p/322009#M2972</guid>
      <dc:creator>AzmathShaik</dc:creator>
      <dc:date>2017-04-17T14:06:17Z</dc:date>
    </item>
  </channel>
</rss>

