Deployment Architecture

Error while running Hunk search: Cannot initialize cluster

Ledion_Bitincka
Splunk Employee
Splunk Employee

I've managed to setup Hunk and run streaming searches without any problem. However when I try to run a reporting search, that starts a MapReduce job the search fails with an error message like this:

JobStartException - Failed to start MapReduce job. Please consult search.log for more information. Message: [Failed to start MapReduce job, name=....] and [Cannot initialize Cluster. Please check your configuration for mapreduce.framework.name and the correspond server addresses.]

Any ideas what could be happening?

Tags (1)
0 Karma
1 Solution

Ledion_Bitincka
Splunk Employee
Splunk Employee

We've seen this error come up a number of times and the error message (thrown by the Hadoop libraries) is misleading. The root cause of the problem in our observations has been a mismatch between the Hadoop client libraries on the Hunk server and Hadoop cluster. Therefore, the first thing you want to do is check that the versions are exactly the same

Just a reminder that Hadoop is very sensitive when it comes to the library versions so we strongly recommend that you use the exact same version as the cluster.

View solution in original post

0 Karma

Ledion_Bitincka
Splunk Employee
Splunk Employee

We've seen this error come up a number of times and the error message (thrown by the Hadoop libraries) is misleading. The root cause of the problem in our observations has been a mismatch between the Hadoop client libraries on the Hunk server and Hadoop cluster. Therefore, the first thing you want to do is check that the versions are exactly the same

Just a reminder that Hadoop is very sensitive when it comes to the library versions so we strongly recommend that you use the exact same version as the cluster.

0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...