Deployment Architecture

replication was unsuccessful. failed_because_REMOTE_CHKSUM_UNMATCHED

sylim_splunk
Splunk Employee
Splunk Employee

Bundle checksum match fails on Search Head hundreds of times per day, we are seeing the same local bundle failing to match the same remote bundle checksum across some indexers.

--- WARN message --
Unable to distribute to peer named mySplunk at uri https://10.1.1.2:8089 because replication was unsuccessful. replicationStatus Failed failure info: failed_because_REMOTE_CHKSUM_UNMATCHED: Remote checksum does not match: remote(mySplunk, 1168766487237572, 1497512449) != local(125317778217050120, 1497512449) Please verify connectivity to the search peer, that the search peer is up, and an adequate level of system resources are available. See the Troubleshooting Manual for more information.

Tags (1)
1 Solution

sylim_splunk
Splunk Employee
Splunk Employee

This turned out to be a defect, of which fix is soon to be released - check with splunk support.

Workaround :
Restart the search-head which is issuing failed checksum warnings during searches. Saved jobs (ie. results from searches stored for further usage) that showed those warnings will not be repaired, they need to be re-ran.

Fixed versions :
6.3.11, 6.4.8, 6.5.5, 6.6.3, 7.0.0

View solution in original post

sylim_splunk
Splunk Employee
Splunk Employee

This turned out to be a defect, of which fix is soon to be released - check with splunk support.

Workaround :
Restart the search-head which is issuing failed checksum warnings during searches. Saved jobs (ie. results from searches stored for further usage) that showed those warnings will not be repaired, they need to be re-ran.

Fixed versions :
6.3.11, 6.4.8, 6.5.5, 6.6.3, 7.0.0

dflodstrom
Builder

I'm seeing this in a 6.6.3 environment

0 Karma

bnorthway_splun
Splunk Employee
Splunk Employee

Which version has this fix?

0 Karma

mbksplunk
Explorer

Encountered this issue today in our env as well. In which version is this being fixed ?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...