Hi,
We are finding that numerous objects and accounts are not replicating across our Search Head Cluster. Are there any troubleshooting steps? Log entries to look at?
Hello,
when you run ./splunk show shcluster-status return all the members?
1. Log on to each and every search head and see if any of them is complaining about "failed to get bundles from captain , perform a destructive resync"?
2. When you say accounts, you mean user accounts? How are you creating user accounts? I can speak about vrsions 6.2 to 6.3.3 (Unless user account is pushed from deployer, SHC members cannot replicaate user accounts(Local splunk authentication). For LDAP, assuming you add folks to an AD group, for immediate effect, refresh LDAP strategy on each search head
3. If you haven't already, use Distributed Management Console to monitor your search head cluster
4. What's you replication factor? and also check the dispatch directory.
Please see: http://docs.splunk.com/Documentation/Splunk/6.4.1/DistSearch/ViewSHCstatusinDMC
Only recommendation with the info provided above, do a rolling-restart wait for all members to be up and captain is elected and try and see if it's replicating.
Hope this helps!
Thanks,
Raghav
I agree with the above and am converting it to an answer.