Deployment Architecture

ReplicationStatus: Failed - Failure info: Dispatch Command: Search bundle throttling

bnakkella
New Member

Hi, I am facing an issue while searching for logs from Search heads. Below are the errors

Distributed: Unable to distribute to peer named INDEXER1 at uri https://10.x.x.1:8089 because replication was unsuccessful. ReplicationStatus: Failed - Failure info: Dispatch Command: Search bundle throttling is occurring because the limit for number of bundles with pending lookups for indexing has been exceeded. This could be the result of large lookup files updating faster than Splunk software can index them. Throttling ends when this instance has caught up with indexing of lookups. If you see this often, contact your Splunk administrator about tuning lookup sizes and max_memtable_bytes.. Please verify connectivity to the search peer, that the search peer is up, and an adequate level of system resources are available. See the Troubleshooting Manual for more information.
Distributed: Unable to distribute to peer named INDEXER2 at uri https://10.x.x.2:8089 because replication was unsuccessful. ReplicationStatus: Failed - Failure info: Dispatch Command: Search bundle throttling is occurring because the limit for number of bundles with pending lookups for indexing has been exceeded. This could be the result of large lookup files updating faster than Splunk software can index them. Throttling ends when this instance has caught up with indexing of lookups. If you see this often, contact your Splunk administrator about tuning lookup sizes and max_memtable_bytes.. Please verify connectivity to the search peer, that the search peer is up, and an adequate level of system resources are available. See the Troubleshooting Manual for more information.

I have increased max_memtable_bytes value in limits.conf from 10MB to 500MB on search heads keeping in mind that this would impact search performance

About our architecture:
• Search head1: Installed Palo Alto, AWS and Linux Apps
• On Search head2: Installed Enterprise Security App
• Two clusterd indexers with SF=1 and RF=2
• 2 non clustered search heads

Thanks!

0 Karma

eavent_splunk
Splunk Employee
Splunk Employee

The unaccepted answer in this post explains this issue well: https://answers.splunk.com/answers/643012/unable-to-distribute-to-peer-from-search-head.html

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...