Deployment Architecture

"Encountered an error deserializing SearchResultsInfo from ResultsStream header." trying to search a Splunk 6.2.4 indexer cluster with a 6.1.5 search head

Lucas_K
Motivator

I have a Search head running Splunk 6.1.5 (can't currently upgrade) and it is trying to search an indexer cluster running on 6.2.4.

It errors out for these particular peers with the error:

08-12-2015 15:11:18.120 ERROR ResultsStream - Encountered an error deserializing SearchResultsInfo from ResultsStream header.

Checking the remote logs from the search peers and there are no errors at all. It's only on the search head.

I've tried readding the cluster master to the search head (removing it, restarting then adding it again) and I get the same issue.

1 Solution

Lucas_K
Motivator

Turns out that this is an unsupported configuration.

Documentation has been updated to reflect the supported version relationships between cluster master, search heads and indexers.

Info here : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Systemrequirements#Splunk_Enterprise_versi...

View solution in original post

Lucas_K
Motivator

Turns out that this is an unsupported configuration.

Documentation has been updated to reflect the supported version relationships between cluster master, search heads and indexers.

Info here : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Systemrequirements#Splunk_Enterprise_versi...

View solution in original post

jeremiahc4
Builder

Getting the exact same error, but our search head and indexer are the same version. The search head member in our case is having difficulty getting the cluster config from the captain.

0 Karma

hzyyollow
New Member

We have encountered the same issue, search a Splunk indexer 6.3.3 and Splunk indexer 6.1.4 with a 6.1.4 search head. Is this a bug or configuration error?

0 Karma

vince2010091
Path Finder

same problem in 6.3.1

0 Karma

KarunK
Contributor

Same Problem as well on 6.3.1

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!