<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to run searches in Splunk Enterprise Security because of the error &amp;quot;BUNDLE_SIZE_EXCEEDS_MAX_SIZE&amp;quot; in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221012#M1349</link>
    <description>&lt;P&gt;I am getting the following error in the Search Head running Splunk Enterprise Security: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Unable to distribute to peer named splunk_1 at uri &lt;A href="https://x.x.x.x:8089" target="test_blank"&gt;https://x.x.x.x:8089&lt;/A&gt; because replication was unsuccessful. replicationStatus Failed failure info: failed_because_BUNDLE_SIZE_EXCEEDS_MAX_SIZE Please verify connectivity to the search peer, that the search peer is up, and an adequate level of system resources are available. See the Troubleshooting Manual for more information.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I did some changes to distsearch.conf file, but the bundle is still over 3 GB in size. &lt;/P&gt;

&lt;P&gt;This is the file stanza: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[replicationSettings]
maxBundleSize = 4096

[replicationSettings]
sendRcvTimeout = 1060

[replicationWhitelist]
allConf = *.conf
allSpec = *.spec

[replicationSettings:refineConf]
replicate.app               = false
replicate.authorize         = true
replicate.collections       = false
replicate.commands          = false
replicate.eventtypes        = false
replicate.fields            = false
replicate.segmenters        = false
replicate.literals          = false
replicate.lookups           = false
replicate.multikv           = false
replicate.props             = true
replicate.tags              = true
replicate.transforms        = true
replicate.transactiontypes  = false

[replicationBlacklist]
nopyc  = apps[/\\]...[/\\](bin|contrib|lib)[/\\]*.py[co]
nopyc2 = apps[/\\]...[/\\](bin|contrib|lib)[/\\]...[/\\]*.py[co]

nocsvdefault = apps[/\\]...[/\\]lookups[/\\]*.csv.default

nolearned = apps[/\\]learned[/\\]...

notracker  = apps[/\\]...[/\\]lookups[/\\]*tracker.csv
notracker2 = apps[/\\]...[/\\]lookups[/\\]*tracker2.csv
nosigref   = apps[/\\]...[/\\]lookups[/\\]*signature_reference.csv
nosigref2  = apps[/\\]...[/\\]lookups[/\\]*signature_reference2.csv


noeditablelookups = apps[/\\]...[/\\]lookups[/\\]editable_lookups.csv

nolegacycontexts = apps[/\\]...[/\\]contexts[/\\]*.context
noconvertedcontexts = apps[/\\]...[/\\]lookups[/\\]*.context.csv.old


noinstallsrc = apps[/\\]SplunkEnterpriseSecuritySuite[/\\]@installsrc@[/\\]...

lookupindexfiles = (system|apps/*|users(/_reserved)?/*/*)/lookups/*.(tmp$|index($|/...))
sampleapp = apps/sample_app/...

conf = (system|(apps/*))/(default|local)/server.conf

user_specific_meta = users(/_reserved)?/*/*/metadata/local.meta
framework = apps/framework/...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 09 Aug 2016 22:01:39 GMT</pubDate>
    <dc:creator>daniel_augustyn</dc:creator>
    <dc:date>2016-08-09T22:01:39Z</dc:date>
    <item>
      <title>Unable to run searches in Splunk Enterprise Security because of the error "BUNDLE_SIZE_EXCEEDS_MAX_SIZE"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221012#M1349</link>
      <description>&lt;P&gt;I am getting the following error in the Search Head running Splunk Enterprise Security: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Unable to distribute to peer named splunk_1 at uri &lt;A href="https://x.x.x.x:8089" target="test_blank"&gt;https://x.x.x.x:8089&lt;/A&gt; because replication was unsuccessful. replicationStatus Failed failure info: failed_because_BUNDLE_SIZE_EXCEEDS_MAX_SIZE Please verify connectivity to the search peer, that the search peer is up, and an adequate level of system resources are available. See the Troubleshooting Manual for more information.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I did some changes to distsearch.conf file, but the bundle is still over 3 GB in size. &lt;/P&gt;

&lt;P&gt;This is the file stanza: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[replicationSettings]
maxBundleSize = 4096

[replicationSettings]
sendRcvTimeout = 1060

[replicationWhitelist]
allConf = *.conf
allSpec = *.spec

[replicationSettings:refineConf]
replicate.app               = false
replicate.authorize         = true
replicate.collections       = false
replicate.commands          = false
replicate.eventtypes        = false
replicate.fields            = false
replicate.segmenters        = false
replicate.literals          = false
replicate.lookups           = false
replicate.multikv           = false
replicate.props             = true
replicate.tags              = true
replicate.transforms        = true
replicate.transactiontypes  = false

[replicationBlacklist]
nopyc  = apps[/\\]...[/\\](bin|contrib|lib)[/\\]*.py[co]
nopyc2 = apps[/\\]...[/\\](bin|contrib|lib)[/\\]...[/\\]*.py[co]

nocsvdefault = apps[/\\]...[/\\]lookups[/\\]*.csv.default

nolearned = apps[/\\]learned[/\\]...

notracker  = apps[/\\]...[/\\]lookups[/\\]*tracker.csv
notracker2 = apps[/\\]...[/\\]lookups[/\\]*tracker2.csv
nosigref   = apps[/\\]...[/\\]lookups[/\\]*signature_reference.csv
nosigref2  = apps[/\\]...[/\\]lookups[/\\]*signature_reference2.csv


noeditablelookups = apps[/\\]...[/\\]lookups[/\\]editable_lookups.csv

nolegacycontexts = apps[/\\]...[/\\]contexts[/\\]*.context
noconvertedcontexts = apps[/\\]...[/\\]lookups[/\\]*.context.csv.old


noinstallsrc = apps[/\\]SplunkEnterpriseSecuritySuite[/\\]@installsrc@[/\\]...

lookupindexfiles = (system|apps/*|users(/_reserved)?/*/*)/lookups/*.(tmp$|index($|/...))
sampleapp = apps/sample_app/...

conf = (system|(apps/*))/(default|local)/server.conf

user_specific_meta = users(/_reserved)?/*/*/metadata/local.meta
framework = apps/framework/...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Aug 2016 22:01:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221012#M1349</guid>
      <dc:creator>daniel_augustyn</dc:creator>
      <dc:date>2016-08-09T22:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run searches in Splunk Enterprise Security because of the error "BUNDLE_SIZE_EXCEEDS_MAX_SIZE"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221013#M1350</link>
      <description>&lt;P&gt;Do you know what's taking up so much space in your bundle?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2016 02:19:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221013#M1350</guid>
      <dc:creator>Jeremiah</dc:creator>
      <dc:date>2016-08-10T02:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run searches in Splunk Enterprise Security because of the error "BUNDLE_SIZE_EXCEEDS_MAX_SIZE"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221014#M1351</link>
      <description>&lt;P&gt;I really don't, how should I check that? &lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2016 16:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221014#M1351</guid>
      <dc:creator>daniel_augustyn</dc:creator>
      <dc:date>2016-08-10T16:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run searches in Splunk Enterprise Security because of the error "BUNDLE_SIZE_EXCEEDS_MAX_SIZE"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221015#M1352</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/DistSearch/Whatsearchheadssend"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/DistSearch/Whatsearchheadssend&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;On the search head, the knowledge bundles resides under the $SPLUNK_HOME/var/run directory.&lt;/P&gt;

&lt;P&gt;The knowledge bundle gets distributed to the $SPLUNK_HOME/var/run/searchpeers directory on each search peer (indexer).&lt;/P&gt;

&lt;P&gt;I'd start on the search heads with a simple &lt;CODE&gt;du -sh /opt/splunk/var/run&lt;/CODE&gt; command (assuming your $SPLUNK_HOME is /opt/splunk&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2016 17:10:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221015#M1352</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-08-10T17:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run searches in Splunk Enterprise Security because of the error "BUNDLE_SIZE_EXCEEDS_MAX_SIZE"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221016#M1353</link>
      <description>&lt;P&gt;I did that and it shows few of 3GB files. The total is 35G of data in that folder. I already did that before but still don't know how to limit that. &lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2016 19:25:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221016#M1353</guid>
      <dc:creator>daniel_augustyn</dc:creator>
      <dc:date>2016-08-10T19:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run searches in Splunk Enterprise Security because of the error "BUNDLE_SIZE_EXCEEDS_MAX_SIZE"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221017#M1354</link>
      <description>&lt;P&gt;Go to the search head and look at the var/run/searchpeers directory.  Copy one of the .bundle files to a temp directory and then untar it.&lt;/P&gt;

&lt;P&gt;cd to the directory and run the command:  &lt;/P&gt;

&lt;P&gt;du -m --max-depth=1&lt;/P&gt;

&lt;P&gt;This will show you the size of the different apps in the bundle.  Find the largest one(s), cd into that and re-run the command.  I suspect that you will find a very large lookup file(s).  You will want to blacklist it in distsearch.conf on the search head.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2016 19:38:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-searches-in-Splunk-Enterprise-Security-because-of/m-p/221017#M1354</guid>
      <dc:creator>sjohnson_splunk</dc:creator>
      <dc:date>2016-08-10T19:38:54Z</dc:date>
    </item>
  </channel>
</rss>

