Deployment Architecture

Bundle action - defining new index fails due to ileagal value of repFactor (auto)

piotrgalas
Explorer

Splunk 7.2 with cluster of 2 indexers.

 

I want to push indexes definitions to peers from master node and the bundle action fails stating that "Auto" is illegal value for repFactor and that the default value is "0".  I want them to replicate so "0" is not an option based on the documentation.  Bundle action is unsuccessful. What could be the reason for this error?

Both peers are up, no errors on the Master Indexer Clustering dashboard.

 

Content of the Master Node indexes.conf in the /opt/splunk/etc/master-apss/_cluster/local/

 

[log_windows]
repFactor = Auto
enableDataIntegrityControl = 0
enableTsidxReduction = 0
maxTotalDataSizeMB = 512000
coldPath = $SPLUNK_DB/log_windows/colddb
homePath = $SPLUNK_DB/log_windows/db
thawedPath = $SPLUNK_DB/log_windows/thaweddb

[pg_test]
repFactor = Auto
enableDataIntegrityControl = 0
enableTsidxReduction = 0
maxTotalDataSizeMB = 512000
coldPath = $SPLUNK_DB/pg_test_kiwi/colddb
homePath = $SPLUNK_DB/pg_test_kiwi/db
thawedPath = $SPLUNK_DB/pg_test_kiwi/thaweddb

 

Errors:

 

Config validation failure reported in peer=sanitized_indexer1 guid=(sanitized_guid_1). stanza=pg_test parameter=repFactor Value supplied='Auto' is illegal; default='0'; stanza=log_windows parameter=repFactor Value supplied='Auto' is illegal; default='0';

Config validation failure reported in peer=sanitized_indexer2 guid=(sanitized_guid_2). stanza=pg_test parameter=repFactor Value supplied='Auto' is illegal; default='0'; stanza=log_windows parameter=repFactor Value supplied='Auto' is illegal; default='0';

 

 

 

 

 

Labels (1)
0 Karma
1 Solution

piotrgalas
Explorer

OK. Thanks to Splunk Support (thanks Guys for fast and swift response) I learned what is the issue.

Correct:
repFactor = auto
Incorrect:
repFactor = Auto

It is case sensitive!

View solution in original post

0 Karma

piotrgalas
Explorer

OK. Thanks to Splunk Support (thanks Guys for fast and swift response) I learned what is the issue.

Correct:
repFactor = auto
Incorrect:
repFactor = Auto

It is case sensitive!

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...