Deployment Architecture

Why am I getting "Unexpected duplicate app..." messages in an indexer cluster?

brent_weaver
Builder

Hey there... I have a Splunk environment with the following architecture:

1 Deployment Server
1 License Server
1 Index Cluster Master
4 Index Slaves/Cluster
3 node search head cluster
1 Search head not in the cluster

I keep getting the following message:

Unexpected duplicate app: cdop_all_indexer_base
        Checking filesystem compatibility...  Done
        Checking conf files for problems...
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
        Done
Unexpected duplicate app: cdop_all_indexer_base
        Checking replication_port port [8091]: Unexpected duplicate app: cdop_al                                                                                                                     l_indexer_base
open
Unexpected duplicate app: cdop_all_indexer_base
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Done
                                                           [  OK  ]

It does look like these are duplicate apps:

indx2:/home/splunk $ find /opt/splunk/etc/ -name cdop_all_indexer_base
/opt/splunk/etc/slave-apps.old/cdop_all_indexer_base
/opt/splunk/etc/slave-apps/cdop_all_indexer_base
/opt/splunk/etc/apps/cdop_all_indexer_base
0 Karma
1 Solution

romiller
Engager

I was able to resolve this same issue by following the docs. In this particular app I was pushing the SSL config settings in the inputs.conf and the docs advises against that and states you will see this error because of this. I had to manually add the lines in that file to each indexer and remove the inputs.conf from the app and that fixed my issue. Hopefully this helps you as well.

http://docs.splunk.com/Documentation/Splunk/6.2.5/Indexer/Updatepeerconfigurations

View solution in original post

romiller
Engager

I was able to resolve this same issue by following the docs. In this particular app I was pushing the SSL config settings in the inputs.conf and the docs advises against that and states you will see this error because of this. I had to manually add the lines in that file to each indexer and remove the inputs.conf from the app and that fixed my issue. Hopefully this helps you as well.

http://docs.splunk.com/Documentation/Splunk/6.2.5/Indexer/Updatepeerconfigurations

romiller
Engager

I am also experiencing the same issue and my app is also similar to yours (i.e. all_indexer_base). Hopefully there is a resolution or a workaround for this.

0 Karma
Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...