Deployment Architecture

Error while running Hunk search: Cannot initialize cluster

Ledion_Bitincka
Splunk Employee
Splunk Employee

I've managed to setup Hunk and run streaming searches without any problem. However when I try to run a reporting search, that starts a MapReduce job the search fails with an error message like this:

JobStartException - Failed to start MapReduce job. Please consult search.log for more information. Message: [Failed to start MapReduce job, name=....] and [Cannot initialize Cluster. Please check your configuration for mapreduce.framework.name and the correspond server addresses.]

Any ideas what could be happening?

Tags (1)
0 Karma
1 Solution

Ledion_Bitincka
Splunk Employee
Splunk Employee

We've seen this error come up a number of times and the error message (thrown by the Hadoop libraries) is misleading. The root cause of the problem in our observations has been a mismatch between the Hadoop client libraries on the Hunk server and Hadoop cluster. Therefore, the first thing you want to do is check that the versions are exactly the same

Just a reminder that Hadoop is very sensitive when it comes to the library versions so we strongly recommend that you use the exact same version as the cluster.

View solution in original post

0 Karma

Ledion_Bitincka
Splunk Employee
Splunk Employee

We've seen this error come up a number of times and the error message (thrown by the Hadoop libraries) is misleading. The root cause of the problem in our observations has been a mismatch between the Hadoop client libraries on the Hunk server and Hadoop cluster. Therefore, the first thing you want to do is check that the versions are exactly the same

Just a reminder that Hadoop is very sensitive when it comes to the library versions so we strongly recommend that you use the exact same version as the cluster.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...