Deployment Architecture

Search head cluster hybrid search: Why error "Gave up waiting for the captain to establish a common bundle version..."?

Lucas_K
Motivator

I'm trying to migrate to a fully clustered environment so I'm trying out hybrid search as a bridge to getting fully clustered.

5x Search head cluster 6.2.1
6x Dist search index members 6.2.1
1x Index cluster master 6.2.1
1x Cluster peers 6.2.1

When performing a search on a search head I get

02-24-2015 14:39:08.539 +1100 WARN  ISplunkDispatch - Gave up waiting for the captain to establish a common bundle version across all search peers; using most recent bundles on all peers instead

This also results in a large pause while this times out.

0 Karma
1 Solution

Lucas_K
Motivator

ok Solved. This error seems occurs when the search head captain can not contact the cluster master.

View solution in original post

Lucas_K
Motivator

ok Solved. This error seems occurs when the search head captain can not contact the cluster master.

sdawsonkg
Path Finder

Would appreciate if you could mention how you arrived at this conclusion or what steps did you follow to rectify the error

0 Karma

Lucas_K
Motivator

lol its been more than 5 years! 😉

Network connectivity between the new hosts on new (at the time) ports wasn't fully enabled as such the communication between members and the cluster master did not work.

If you see this error now (in the year 2020) this can be caused by other different issues such as the bundle being too large.

JustAnotherITG
Explorer

@Lucas_K wrote:

lol its been more than 5 years! 😉

Network connectivity between the new hosts on new (at the time) ports wasn't fully enabled as such the communication between members and the cluster master did not work.

If you see this error now (in the year 2020) this can be caused by other different issues such as the bundle being too large.


Just here to give you +1 Karma for answering a question FIVE YEARS LATER. and then elaborating on it for the applicability of the current year (2020). your +1 karma is 2yrs late.. I got here as fast as I could

Lucas_K
Motivator

Actually I think I know what this issue is. The captain must be having trouble getting the peer list from the cluster master. As such it can't know which search peers it needs to send the shc bundles to.

I will check tomorrow 🙂

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...