Deployment Architecture

Why is my SHC captain reporting the error that it can't connect to the (previous) captain?

twinspop
Influencer

My SHC captain is reporting this:

Search peer <current_captain> has the following message: The search head cluster captain (https://<previous_captain>:8089) is disconnected; skipping configuration replication

I've since run a rolling restart, but the message persists.

0 Karma

Masa
Splunk Employee
Splunk Employee

In general, you will find more errors or warnings around that message. Sometimes it is related to bundle from deployer.
Other time, it is related to configuration replication errors due to corrupted file or large contents or something. If you find which file or configuration is related to this error, you can try to delete or remove it and see if it helps.

For detail of troubleshooting, you might want to file a Support case with a splunk diag file so that Support engineer can take look into more detail.

0 Karma

Lucas_K
Motivator

Is the previous captain actually running?

Check that the cluster is in a working state? Check with the status command.

0 Karma

twinspop
Influencer

Yes. Cluster is 100% up. Previous captain reporting normally.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...