Deployment Architecture

SHC Captain Disconnected

MFiller90
Explorer

Hey Splunkers,

It seems that several times per hour that our SHC (of 9 SH's) seems to randomley disconnect the SHC Captain. We only ever see the "pumpkins" in the top on the search head GUIs. Something to the effect of "Search Head Captain disconnected blah blah"

The fun part is that, nothing actually bad happens. Our searches continue to run and complete. The errors eventually disappear after about 45 seconds. The annoying part is that if the timing is right, and you try to push a new bundle via Deployer --> SHC, the Deployer says "No captain found amongst members". To which, we just repush and it magically goes through just fine.

Running Splunk Enterprise v7.0.5

Has anybody ever seen anything similar to this?

Thanks!

Tags (2)
0 Karma

nareshinsvu
Builder

Might be network glitches? Do you see any errors in your splunkd.log?

For detail of troubleshooting, you might want to file a Support case with a splunk diag file so that Support engineer can take look into more detail.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...