Deployment Architecture

Distributed Search Knowledge Bundle Regex

Splunker
Communicator

Folks,

I have a Splunk 4.2.4 search-head and indexer on another machine in a distributed setup.

I'm getting an error in my splunkd.log about my knowledge bundle timing out replicating from search-head to indexer.

I've tried the following in my distsearch.conf:

[replicationWhitelist]
allConf = *.conf
allSpec = *.spec

Based on the Splunk docs. Looking in $SPLUNK_HOME/var/run/searchpeers/(latest).bundle on the indexer i see all sorts of files in the tarball not just the ones i've allowed via my whitelist.

I've restarted both search-head & indexer and am not sure what to try next? Do i also need a global blacklist?

Thanks.

Tags (1)
0 Karma
1 Solution

Splunker
Communicator

I managed to fix the above problem after realising the regex's need the full path to the offending large files.

*.conf seems to only match in the root-level directories ($SPLUNK_HOME/etc /users /etc/apps, etc..)

Something like (i had a large lookup list in my Google Maps and MAXMIND app (the geoip DB)):

[replicationBlacklist]
AppMapsCSV = maps/local/*.csv
AppMaxMindCSV = MAXMIND/local/*.csv

Did the trick, which significantly dropped my knowledge bundle size to something more manageable.

Hope it helps someone 🙂

View solution in original post

Splunker
Communicator

I managed to fix the above problem after realising the regex's need the full path to the offending large files.

*.conf seems to only match in the root-level directories ($SPLUNK_HOME/etc /users /etc/apps, etc..)

Something like (i had a large lookup list in my Google Maps and MAXMIND app (the geoip DB)):

[replicationBlacklist]
AppMapsCSV = maps/local/*.csv
AppMaxMindCSV = MAXMIND/local/*.csv

Did the trick, which significantly dropped my knowledge bundle size to something more manageable.

Hope it helps someone 🙂

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...