Deployment Architecture

Search Head - Splunkd.log

mldaplin
Engager

Hi,

I'm always getting these error logs on my search head splunkd.log.

01-27-2011 12:01:31.398 WARN DistributedBundleReplicationManager - Unable to login to remote peer at http://10.163.97.13:8089 named SILAPD03 with username splunk-system-user 01-27-2011 12:01:36.402 WARN DistributedBundleReplicationManager - Server SILAPD03[http://10.163.97.13:8089] does not support distributed bundle exchange, probably because it is an older version. Giving up due to error code 401. 01-27-2011 12:01:36.402 ERROR DistributedBundleReplicationManager - Unable to get remote checksum from peer named SILAPD03 with uri=http://10.163.97.13:8089 01-27-2011 12:01:36.808 INFO TPool - All 1 workers of BundleReplThreadPool terminated 01-27-2011 12:01:36.808 WARN DistributedBundleReplicationManager - bundle replication to 3 peer(s) took too long (35759ms), bundle file size=5970KB

Many times have I changed my password I'm always getting unable to login...

Please help!

Regards, Marlon

Tags (1)

Ayn
Legend

I'm having the same problems unfortunately, and can't use a solution with mounted bundles 😕

0 Karma

jfolkers
New Member

Marlon,

I had this same issue. In my case, I had multiple splunk instances on the same linux server all working just fine, but bundle replication didn't seem to work. Like your post above, I too had these events in splunkd.log, "WARN DistributedBundleReplicationManager - Server indexer1 does not support distributed bundle exchange, probably because it is an older version. Giving up due to error code 401." etc.

All splunk instances are running the same 4.2.1 code, so I'm sure it's not due to an older version.

My workaround was to use mounted bundles and turn off bundle replication.

So, on each indexer in $SPLUNK_HOME/etc/system/local, I put this in distsearch.conf
[searchhead:searchhead1]
mounted_bundles = true
bundles_location = /opt/shared_bundles/searchhead1

Docs are here.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...