Deployment Architecture

"Encountered an error deserializing SearchResultsInfo from ResultsStream header." trying to search a Splunk 6.2.4 indexer cluster with a 6.1.5 search head

Lucas_K
Motivator

I have a Search head running Splunk 6.1.5 (can't currently upgrade) and it is trying to search an indexer cluster running on 6.2.4.

It errors out for these particular peers with the error:

08-12-2015 15:11:18.120 ERROR ResultsStream - Encountered an error deserializing SearchResultsInfo from ResultsStream header.

Checking the remote logs from the search peers and there are no errors at all. It's only on the search head.

I've tried readding the cluster master to the search head (removing it, restarting then adding it again) and I get the same issue.

1 Solution

Lucas_K
Motivator

Turns out that this is an unsupported configuration.

Documentation has been updated to reflect the supported version relationships between cluster master, search heads and indexers.

Info here : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Systemrequirements#Splunk_Enterprise_versi...

View solution in original post

Lucas_K
Motivator

Turns out that this is an unsupported configuration.

Documentation has been updated to reflect the supported version relationships between cluster master, search heads and indexers.

Info here : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Systemrequirements#Splunk_Enterprise_versi...

jeremiahc4
Builder

Getting the exact same error, but our search head and indexer are the same version. The search head member in our case is having difficulty getting the cluster config from the captain.

0 Karma

hzyyollow
New Member

We have encountered the same issue, search a Splunk indexer 6.3.3 and Splunk indexer 6.1.4 with a 6.1.4 search head. Is this a bug or configuration error?

0 Karma

vince2010091
Path Finder

same problem in 6.3.1

0 Karma

KarunK
Contributor

Same Problem as well on 6.3.1

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...