<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Downloaded an old snapshot created 485320 seconds ago in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Downloaded-an-old-snapshot-created-485320-seconds-ago/m-p/491871#M8394</link>
    <description>&lt;P&gt;As part of the destructive resync that I performed on the 2 members that were out of sync, I saw the below messages on the SH’s after process completion.&lt;/P&gt;

&lt;P&gt;They have downloaded a snapshot from the captain that is 5 days old.&lt;/P&gt;

&lt;P&gt;Does this mean that the Captain does not have a common that is recent than 5 days.&lt;/P&gt;

&lt;P&gt;--- resync and results --&lt;BR /&gt;
 $ splunk resync shcluster-replicated-config&lt;BR /&gt;
Your session is invalid. Please login.&lt;BR /&gt;
Splunk username: admin&lt;BR /&gt;
Password:&lt;/P&gt;

&lt;P&gt;Downloaded an old snapshot created 485324 seconds ago; Check for clock skew on this member or the captain; If no clock skew is found, check the captain for possible snapshot creation failures*&lt;/P&gt;</description>
    <pubDate>Tue, 01 Oct 2019 18:54:12 GMT</pubDate>
    <dc:creator>sylim_splunk</dc:creator>
    <dc:date>2019-10-01T18:54:12Z</dc:date>
    <item>
      <title>Downloaded an old snapshot created 485320 seconds ago</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Downloaded-an-old-snapshot-created-485320-seconds-ago/m-p/491871#M8394</link>
      <description>&lt;P&gt;As part of the destructive resync that I performed on the 2 members that were out of sync, I saw the below messages on the SH’s after process completion.&lt;/P&gt;

&lt;P&gt;They have downloaded a snapshot from the captain that is 5 days old.&lt;/P&gt;

&lt;P&gt;Does this mean that the Captain does not have a common that is recent than 5 days.&lt;/P&gt;

&lt;P&gt;--- resync and results --&lt;BR /&gt;
 $ splunk resync shcluster-replicated-config&lt;BR /&gt;
Your session is invalid. Please login.&lt;BR /&gt;
Splunk username: admin&lt;BR /&gt;
Password:&lt;/P&gt;

&lt;P&gt;Downloaded an old snapshot created 485324 seconds ago; Check for clock skew on this member or the captain; If no clock skew is found, check the captain for possible snapshot creation failures*&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 18:54:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Downloaded-an-old-snapshot-created-485320-seconds-ago/m-p/491871#M8394</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2019-10-01T18:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Downloaded an old snapshot created 485320 seconds ago</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Downloaded-an-old-snapshot-created-485320-seconds-ago/m-p/491872#M8395</link>
      <description>&lt;P&gt;I found error messages repeating as below, which suggests it has been failing for days.&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;09-18-2019 18:35:58.803 +0000 ERROR ConfReplication - Error creating snapshot: /opt/splunk/var/run/splunk/snapshot/15831677-5b6c4f95a711c6431341ba397e4c6b012a.bundle.f3effb6944a1e.tmp; Configurations changed while generating snapshot, original_latest_change=5b6c4f95a711c6431341ba397e4c6b012a, new_latest_change=2f2baeb33f5867261227d7636d5c7ed3b0d38749; consecutiveRejectionFromNewChanges=&lt;/EM&gt;&lt;EM&gt;336;&lt;/EM&gt;* Check conf.log to see if any app or client is making frequent configuration changes; Continuous snapshot creation failures can lead to configuration replication issues if this member becomes the captain*&lt;/P&gt;

&lt;P&gt;As it suggests in the message above the conf.log shows a lot of changes "addCommit" from ES import, due to this it updates local.meta and interrupts the creation of snapshot.&lt;/P&gt;

&lt;P&gt;== Use the below searches to identify the changes that interrupts the operation ==&lt;BR /&gt;
index=_internal source=*/splunkd.log consecutiveRejectionFromNewChanges&amp;nbsp; earliest=-1d latest=now&lt;/P&gt;

&lt;P&gt;Index=_internal source=&lt;EM&gt;/conf.log&lt;/EM&gt; source=*/conf.log* data.task=addCommit| timechart span=5m count by data.optype_desc  &lt;/P&gt;

&lt;P&gt;Especially this issue was caused by the ES import modular input which updates several 100s of apps and add-ons installed on the SH. The import operation is only needed when new apps/add-ons installed on the server, without it ES will not recognize the data to be monitored.&lt;BR /&gt;
This has been worked around by increasing the interval to, like 2hrs, for ES import mod input, which is in  inputs.conf of /etc/apps/SplunkEnterpriseSecuritySuite, this import has been removed in the latest version of ESS 5.3.1.&lt;/P&gt;

&lt;P&gt;It depends on the deployments environment - this time it was caused by ES import but there could be some other apps/add-on which could frequently update the configs.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:22:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Downloaded-an-old-snapshot-created-485320-seconds-ago/m-p/491872#M8395</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2020-09-30T02:22:13Z</dc:date>
    </item>
  </channel>
</rss>

