Deployment Architecture

Search head cluster hybrid search: Why error "Gave up waiting for the captain to establish a common bundle version..."?

Lucas_K
Motivator

I'm trying to migrate to a fully clustered environment so I'm trying out hybrid search as a bridge to getting fully clustered.

5x Search head cluster 6.2.1
6x Dist search index members 6.2.1
1x Index cluster master 6.2.1
1x Cluster peers 6.2.1

When performing a search on a search head I get

02-24-2015 14:39:08.539 +1100 WARN  ISplunkDispatch - Gave up waiting for the captain to establish a common bundle version across all search peers; using most recent bundles on all peers instead

This also results in a large pause while this times out.

0 Karma
1 Solution

Lucas_K
Motivator

ok Solved. This error seems occurs when the search head captain can not contact the cluster master.

View solution in original post

Lucas_K
Motivator

ok Solved. This error seems occurs when the search head captain can not contact the cluster master.

sdawsonkg
Path Finder

Would appreciate if you could mention how you arrived at this conclusion or what steps did you follow to rectify the error

0 Karma

Lucas_K
Motivator

lol its been more than 5 years! 😉

Network connectivity between the new hosts on new (at the time) ports wasn't fully enabled as such the communication between members and the cluster master did not work.

If you see this error now (in the year 2020) this can be caused by other different issues such as the bundle being too large.

JustAnotherITG
Explorer

@Lucas_K wrote:

lol its been more than 5 years! 😉

Network connectivity between the new hosts on new (at the time) ports wasn't fully enabled as such the communication between members and the cluster master did not work.

If you see this error now (in the year 2020) this can be caused by other different issues such as the bundle being too large.


Just here to give you +1 Karma for answering a question FIVE YEARS LATER. and then elaborating on it for the applicability of the current year (2020). your +1 karma is 2yrs late.. I got here as fast as I could

Lucas_K
Motivator

Actually I think I know what this issue is. The captain must be having trouble getting the peer list from the cluster master. As such it can't know which search peers it needs to send the shc bundles to.

I will check tomorrow 🙂

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...