Deployment Architecture

How to troubleshoot why accounts and objects are not replicating in our Search Head Cluster?

a212830
Champion

Hi,

We are finding that numerous objects and accounts are not replicating across our Search Head Cluster. Are there any troubleshooting steps? Log entries to look at?

0 Karma

Raghav2384
Motivator

Hello,

when you run ./splunk show shcluster-status return all the members?
1. Log on to each and every search head and see if any of them is complaining about "failed to get bundles from captain , perform a destructive resync"?
2. When you say accounts, you mean user accounts? How are you creating user accounts? I can speak about vrsions 6.2 to 6.3.3 (Unless user account is pushed from deployer, SHC members cannot replicaate user accounts(Local splunk authentication). For LDAP, assuming you add folks to an AD group, for immediate effect, refresh LDAP strategy on each search head
3. If you haven't already, use Distributed Management Console to monitor your search head cluster
4. What's you replication factor? and also check the dispatch directory.
Please see: http://docs.splunk.com/Documentation/Splunk/6.4.1/DistSearch/ViewSHCstatusinDMC

Only recommendation with the info provided above, do a rolling-restart wait for all members to be up and captain is elected and try and see if it's replicating.

Hope this helps!

Thanks,
Raghav

0 Karma

jkat54
SplunkTrust
SplunkTrust

I agree with the above and am converting it to an answer.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...