Deployment Architecture

Can anyone help me understand "genid thats invalid or out of range" and "Proxy is in disconnect state" warning messages from my indexer cluster?

lycollicott
Motivator

We have an indexer which is going to be down for several days, so in preparation for that I performed these steps:

  • splunk offline on site1 indexer
  • Changed server.conf on the cluster master node from this

    • site_replication_factor = origin:1,site1:1,site2:1,total:2 site_search_factor = origin:1,site1:1,site2:1,total:2
  • To this

    • site_replication_factor = origin:1,total:1 site_search_factor = origin:1,total:1
  • Bounced cluster master

I thought that would prevent search & replication messages from cluttering splunkd.log while site1 was unavailable, but I am getting this combination of warnings about 1500 times an hour:

WARN  CMMessages - got genid thats invalid or out of range, setting to INVALID_GENID, jn=18446744073709551616.000000
WARN  CMSlave - handleHeartbeatDone: successful heartbeat. Forcing a re-add, Reason="Proxy is in disconnect state."

The system also seems to think that the indexes are not fully searchable, but I think that there is a primary bucket for everything the remaining site2.

Should I do anything about these warnings?

0 Karma
1 Solution

lycollicott
Motivator

I just realized that I never updated this with what I figured out.

On the cluster master ( etc\system\local\server.conf) I had to change this:

available_sites = site1, site2

to this:

available_sites = site2

View solution in original post

lycollicott
Motivator

I just realized that I never updated this with what I figured out.

On the cluster master ( etc\system\local\server.conf) I had to change this:

available_sites = site1, site2

to this:

available_sites = site2

woodcock
Esteemed Legend

I would open a support case.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...