Deployment Architecture

Why does the cluster master throw error "Archiver failure - Failed to create archive file" on cluster-bundle push?

ejharts2015
Communicator

Oftentimes when we go to deploy our configs to our clustered indexers (Splunk 6.3.0) using:

sudo -H -u splunk /opt/splunk/bin/splunk apply cluster-bundle

It fails with the following error:

Encountered some errors while applying the bundle.

 In handler 'clustermastercontrol': The Master could not push the latest configuration bundle because it contains an invalid configuration. Fix any errors and push the bundle again. Alternatively, you can skip the validation process like this: "splunk apply cluster-bundle --skip-validation". Use this option carefully, as it can cause the master to push an invalid configuration to the peers. The following errors were encountered: 
Archiver failure - Failed to create archive file.

Any ideas how to fix or what this means? Can't seem to find others with this issue.

0 Karma
1 Solution

ejharts2015
Communicator

Finally figured this one out. Turns out the permissions were invalid on the file we had just created (they were created/owned by root). To fix we ran a:

sudo chown -R splunk:splunk /opt/splunk/etc/...file.conf

Then repushed the bundle. And it worked.

The other time we had this issue, someone else had one of the conf files open in vim (which automatically creates a .swp file) which prevented the push.

View solution in original post

ejharts2015
Communicator

Finally figured this one out. Turns out the permissions were invalid on the file we had just created (they were created/owned by root). To fix we ran a:

sudo chown -R splunk:splunk /opt/splunk/etc/...file.conf

Then repushed the bundle. And it worked.

The other time we had this issue, someone else had one of the conf files open in vim (which automatically creates a .swp file) which prevented the push.

Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...