Archive

upgrade 6.5.4 to 6.6.1 --> The searchhead is unable to update the peer information

zitom
Explorer

Error:

The searchhead is unable to update the peer information. Error = 'Couldn't deserialize, err=Deserialization failed parsing unsigned long long. key=num_buckets not found in json=......

help me please

Tags (1)

nikita_p
Contributor

Hi @zitom,
I think you are getting that error because Splunk has strict versioning requirements within indexer clustering.

The cluster Master Node version must be greater than or equal to the Search Head.
The Search Head version must be greater than or equal to Search Peers.
ie. CM version => SH version => peers version

0 Karma

cudgel
Path Finder

This appears to be an error from an indexer cluster master. If the cluster master is not at 6.6 the search head cannot be upgraded to that version. The indexers in the cluster do not need to be 6.6.

sahr
Path Finder

I second this. We had a distributed peering environment with other agencies and once we removed the lower version Clustermaster, the error went away.

Once upgraded to a compatible version, the warnings/error should go away.

Btw...we had 7.0.1 on our SHs and the troubled Clustermaster was at 6.5.3 I believe.

0 Karma

adonio
SplunkTrust
SplunkTrust

windows or linux?
can you describe the upgrade process? seems like you have search heads and indexers, is that true?

0 Karma

zitom
Explorer

The searchhead is in windows environment
We have data in cloud and we use the locally installed searchhead to access the data
Before the upgrade everything worked
After lupgrede does not work the searches

0 Karma

adonio
SplunkTrust
SplunkTrust

is the search head up?
please describe your upgrade process in detail

0 Karma

zitom
Explorer

Setup is standard in the sense that I downloaded the 64bit file and launched it on the searchead machine
Then I just wait for some setup to finish
I'm afraid there is cloud incompatibility where we have data and searchead where we read them

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!