Deployment Architecture

Why am I unable to apply search head cluster bundle?

martaBenedetti
Path Finder

Hi community,

I've just performed an upgrade on my infrastructure (distributed environment) from Splunk 8.2.3 to Splunk 9.0.3.

All the instances seem to work fine, I have problems though in applying search head cluster bundle.

I use this command to upgrade Splunk Enterprise Security:

 

$SPLUNK_HOME/bin/splunk apply shcluster-bundle -preserve-lookups true -target https://instance1:8089

 

 

But it doesn't work and I receive this message:

 

Error while deploying apps to first member, aborting apps deployment to all members: Error while updating app=SplunkEnterpriseSecuritySuite on target=https://instance1:8089: Error in JSON response: Unexpected EOF

 

 

Do you have any idea of what could be the problem?

 

Thank you

Marta

Labels (3)
0 Karma
1 Solution

gcusello
Esteemed Legend

Hi @martaBenedetti,

I encountered a similar problem (not on ES) caused by too few disk space on the Deployer.

But anyway, immediately open a case to Splunk Support.

Ciao.

Giuseppe

 

View solution in original post

gcusello
Esteemed Legend

Hi @martaBenedetti,

I encountered a similar problem (not on ES) caused by too few disk space on the Deployer.

But anyway, immediately open a case to Splunk Support.

Ciao.

Giuseppe

 

Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...