Deployment Architecture

failed_because_BUNDLE_DATA_TRANSMIT_FAILURE

Venkataraman
Engager

Dear Team,

We have a cluster step up where 3 search head(cluster) , 3 indexer(cluster),1 index master,1 deployer, 1 license master
We are getting below mentioned errors in the production system in one of the search head.

Error Message: "Unable to distribute to peer named xxx5012.xxxx.com at uri https://xx.41.xxx.xx:8089 because replication was unsuccessful. replicationStatus Failed failure info: failed_because_BUNDLE_DATA_TRANSMIT_FAILURE Please verify connectivity to the search peer, that the search peer is up, and an adequate level of system resources are available. See the Troubleshooting Manual for more information."

Can you please help us in solving it.

Regards,
Santosh

0 Karma

nawazns5038
Builder

Did you check the bundle size that you are sending from the search heads to the indexers ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have followed the suggestions in the error message? Verified the SH can connect to the indexer? Checked the resources on the indexer? Read the Troubleshooting manual?

---
If this reply helps you, Karma would be appreciated.

Venkataraman
Engager

Hi Richgalloway,

Thanks for replying.

We are looking into them already without any luck so far. Just to add to the above, we have recently upgraded our system.
SH's : c4.8x to c5.18x
Indexer: c4.8x to c5.9x
deployer:c4.8x to c5.9x
index master: c4.8x to c5.9x
license manager: c4.8x to c5.9x

Do we need to re authenticate search heads and indexers after upgrading?

Regards,
Santosh.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Someone else will have to answer that question.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...