Deployment Architecture

Why do I often see error "Asynchronous bundle replication to 2 peer(s) succeeded; however it took too long..." and how do I fix this?

splunkdevabhi
Explorer

I see these bundle replication errors very often. Is there a solution or workaround?

02-15-2016 22:56:38.636 -0800 ERROR DistributedBundleReplicationManager - Unexpected problem while uploading bundle: Unknown write error
02-15-2016 22:56:38.636 -0800 ERROR DistributedBundleReplicationManager - Unable to upload bundle to peer named xyz with uri=https://xx.xx.xx.xx:8089.
02-15-2016 22:56:38.637 -0800 WARN  DistributedBundleReplicationManager - Asynchronous bundle replication to 2 peer(s) succeeded; however it took too long (longer than 10 seconds): elapsed_ms=37649, tar_elapsed_ms=23682, bundle_file_size=939470KB, replication_id=1455605760, replication_reason="async replication allowed"
1 Solution

DavidHourani
Super Champion

Some suggestions:

1- Check the permissions of your bundle files to make sure your SH can access and push them.
2- Make sure your bundle doesn't exceed the limit (In your logs I see that the size is 939470KB, default size is 800MB so you're exceeding it).
3- Make sure you check the content of your bundle using the ID.

Regards,
David

View solution in original post

DavidHourani
Super Champion

Some suggestions:

1- Check the permissions of your bundle files to make sure your SH can access and push them.
2- Make sure your bundle doesn't exceed the limit (In your logs I see that the size is 939470KB, default size is 800MB so you're exceeding it).
3- Make sure you check the content of your bundle using the ID.

Regards,
David

lycollicott
Motivator

Is your bundle being sent to a remote site across a site-to-site VPN tunnel?

0 Karma

DavidHourani
Super Champion

Any solution ? im having the same problem..

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...