Deployment Architecture

Why am I getting "Unexpected duplicate app..." messages in an indexer cluster?

brent_weaver
Builder

Hey there... I have a Splunk environment with the following architecture:

1 Deployment Server
1 License Server
1 Index Cluster Master
4 Index Slaves/Cluster
3 node search head cluster
1 Search head not in the cluster

I keep getting the following message:

Unexpected duplicate app: cdop_all_indexer_base
        Checking filesystem compatibility...  Done
        Checking conf files for problems...
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
        Done
Unexpected duplicate app: cdop_all_indexer_base
        Checking replication_port port [8091]: Unexpected duplicate app: cdop_al                                                                                                                     l_indexer_base
open
Unexpected duplicate app: cdop_all_indexer_base
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Done
                                                           [  OK  ]

It does look like these are duplicate apps:

indx2:/home/splunk $ find /opt/splunk/etc/ -name cdop_all_indexer_base
/opt/splunk/etc/slave-apps.old/cdop_all_indexer_base
/opt/splunk/etc/slave-apps/cdop_all_indexer_base
/opt/splunk/etc/apps/cdop_all_indexer_base
0 Karma
1 Solution

romiller
Engager

I was able to resolve this same issue by following the docs. In this particular app I was pushing the SSL config settings in the inputs.conf and the docs advises against that and states you will see this error because of this. I had to manually add the lines in that file to each indexer and remove the inputs.conf from the app and that fixed my issue. Hopefully this helps you as well.

http://docs.splunk.com/Documentation/Splunk/6.2.5/Indexer/Updatepeerconfigurations

View solution in original post

romiller
Engager

I was able to resolve this same issue by following the docs. In this particular app I was pushing the SSL config settings in the inputs.conf and the docs advises against that and states you will see this error because of this. I had to manually add the lines in that file to each indexer and remove the inputs.conf from the app and that fixed my issue. Hopefully this helps you as well.

http://docs.splunk.com/Documentation/Splunk/6.2.5/Indexer/Updatepeerconfigurations

View solution in original post

romiller
Engager

I am also experiencing the same issue and my app is also similar to yours (i.e. all_indexer_base). Hopefully there is a resolution or a workaround for this.

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.