Deployment Architecture

How to troubleshoot why accounts and objects are not replicating in our Search Head Cluster?

a212830
Champion

Hi,

We are finding that numerous objects and accounts are not replicating across our Search Head Cluster. Are there any troubleshooting steps? Log entries to look at?

0 Karma

Raghav2384
Motivator

Hello,

when you run ./splunk show shcluster-status return all the members?
1. Log on to each and every search head and see if any of them is complaining about "failed to get bundles from captain , perform a destructive resync"?
2. When you say accounts, you mean user accounts? How are you creating user accounts? I can speak about vrsions 6.2 to 6.3.3 (Unless user account is pushed from deployer, SHC members cannot replicaate user accounts(Local splunk authentication). For LDAP, assuming you add folks to an AD group, for immediate effect, refresh LDAP strategy on each search head
3. If you haven't already, use Distributed Management Console to monitor your search head cluster
4. What's you replication factor? and also check the dispatch directory.
Please see: http://docs.splunk.com/Documentation/Splunk/6.4.1/DistSearch/ViewSHCstatusinDMC

Only recommendation with the info provided above, do a rolling-restart wait for all members to be up and captain is elected and try and see if it's replicating.

Hope this helps!

Thanks,
Raghav

0 Karma

jkat54
SplunkTrust
SplunkTrust

I agree with the above and am converting it to an answer.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...