Deployment Architecture

Issues with search head members pushing configs to captain

lmvmandadi
Engager

I am getting the below error
Search head cluster member (https://hesplsrhc001:8089) is having problems pushing configurations to the search head cluster captain (https://hesplsrhc004:8089). Changes on this member are not replicating to other members

0 Karma

amartin6
Path Finder

We had the same issue, we looked in _internal and found that there was a large lookup:

index=_internal sourcetype=splunkd "is having problems pushing configurations to the search head cluster captain"

ERROR ConfReplicationThread [5001 ConfReplicationThread] - Error pushing configurations to captain=https://xxx.xxx.xx.xx:8089, consecutiveErrors=1678 msg="Error in acceptPush, uploading lookup_table_file="/apps/splunk/etc/apps/search/lookups/xxx.csv": Non-200 status_code=413: Content-Length of 5452600466 too large (maximum is 5000000000)": Search head cluster member (https://xxx.xxx.xx.xx:8089) is having problems pushing configurations to the search head cluster captain (https://xxx.xxx.xx.xx:8089). Changes on this member are not replicating to other members.

The lookup was 5GB, we decreased the size of the lookup and the error no longer appeared on the monitoring console or in _internal

ridwanahmed
Path Finder

did you ever figure this out? 

Tags (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

That could be because member which is trying to notify changes happened to captain is out of sync from other members. 

try to do rolling restart of search head cluster.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...