Deployment Architecture

"Encountered an error deserializing SearchResultsInfo from ResultsStream header." trying to search a Splunk 6.2.4 indexer cluster with a 6.1.5 search head

Lucas_K
Motivator

I have a Search head running Splunk 6.1.5 (can't currently upgrade) and it is trying to search an indexer cluster running on 6.2.4.

It errors out for these particular peers with the error:

08-12-2015 15:11:18.120 ERROR ResultsStream - Encountered an error deserializing SearchResultsInfo from ResultsStream header.

Checking the remote logs from the search peers and there are no errors at all. It's only on the search head.

I've tried readding the cluster master to the search head (removing it, restarting then adding it again) and I get the same issue.

1 Solution

Lucas_K
Motivator

Turns out that this is an unsupported configuration.

Documentation has been updated to reflect the supported version relationships between cluster master, search heads and indexers.

Info here : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Systemrequirements#Splunk_Enterprise_versi...

View solution in original post

Lucas_K
Motivator

Turns out that this is an unsupported configuration.

Documentation has been updated to reflect the supported version relationships between cluster master, search heads and indexers.

Info here : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Systemrequirements#Splunk_Enterprise_versi...

jeremiahc4
Builder

Getting the exact same error, but our search head and indexer are the same version. The search head member in our case is having difficulty getting the cluster config from the captain.

0 Karma

hzyyollow
New Member

We have encountered the same issue, search a Splunk indexer 6.3.3 and Splunk indexer 6.1.4 with a 6.1.4 search head. Is this a bug or configuration error?

0 Karma

vince2010091
Path Finder

same problem in 6.3.1

0 Karma

KarunK
Contributor

Same Problem as well on 6.3.1

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...