Deployment Architecture

Why am I getting repeated message "WARN DispatchThread - Can not download search.log from peer '' because no remote sid was received."?

ncsantucci
Path Finder

WARN DispatchThread - Can not download search.log from peer '<FQDN>' because no remote sid was received.

This warning shows up on a single ad hoc search head, once for each indexer <FQDN> which is configured as a search peer, repeating every 20-30 seconds.

This is a lot of noise in splunkd.log and I would like to get to the bottom of this because I believe this degrades performance even being a physical search head due to error frequency.

0 Karma

ncsantucci
Path Finder

It turns out that this particular search head was on a different VLAN than all my other ad-hoc search heads and search head pool members. Furthermore, there was a network issue (router issues) between the search head in question and the target indexers.
When the network connectivity was restored, I re-entered the password for the search peers (indexers) and then everything was fine.

0 Karma

ncsantucci
Path Finder

Correction: I saw the error re-appear, so the exact root cause it unknown!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...