Deployment Architecture

Failed to create a bundles setup with server name 'GUID'.

xisura
Communicator

Hi ,

Im trying to connect the sh cluster to indexer cluster,Im using Splunk Version 7. All the status are ok.
But everytime i will query a search this error shows up

[idx1] [idx2] [idx3] Failed to create a bundles setup with server name 'GUID'. Using peer's local bundles to execute the search, results might not be correct

in splunkd.log it shows

10-01-2017 22:01:43.115 +0800 WARN ISplunkDispatch - Gave up waiting for the captain to establish a common bundle version across all search peers; using most recent bundles on all peers instead

Please enlighten me

Thanks in Advance

0 Karma
1 Solution

xisura
Communicator

This error will show up if one of the sh cluster member doesn't have the same no. of search peers

View solution in original post

xisura
Communicator

This error will show up if one of the sh cluster member doesn't have the same no. of search peers

bandit
Motivator

Thanks for the solution @xisura. In verion 7.0.x the feature to replicate the search peers config to other members of the search cluster didn't work for me so I had to use a script/command line on each search cluster member to add all peers.

# when scripted from a remote host
ssh -n [SEARCH_HEAD] "/opt/splunk/bin/splunk add search-server https://[SEARCH_PEER]:8089 -auth [LOCAL_ADMIN_ACCOUNT]:[LOCAL_ADMIN_PASS] -remoteUsername [REMOTE_USER] -remotePassword [REMOTE_PASS]"

OR

# locally 
/opt/splunk/bin/splunk add search-server https://[SEARCH_PEER]:8089 -auth [LOCAL_ADMIN_ACCOUNT]:[LOCAL_ADMIN_PASS] -remoteUsername [REMOTE_USER] -remotePassword [REMOTE_PASS]
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...