Getting Data In

Bundle Replication Issue

ShaneNewman
Motivator

I have an indexer that seems to be having an issue keeping up with bundles with Splunk 5.0.5. I have been though S.O.S. looking for a cause, the only thing I see in the logs are timeouts waiting for the indexer to receive the bundle. There are 4 servers that maintain bundles with this indexer. This indexer is connected via fiber (10G).

Anyone have any ideas what is going on or where I could look to get more insight into this problem?

0 Karma
1 Solution

adityapavan18
Contributor

Shane, how big are the bundle files?

You can refer this

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch#Limit_the_knowledg...

And see if the smaller bundles are being pushed without a timeout

View solution in original post

adityapavan18
Contributor

Shane, how big are the bundle files?

You can refer this

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch#Limit_the_knowledg...

And see if the smaller bundles are being pushed without a timeout

ShaneNewman
Motivator

I found the issue after getting into the searchpeers folder. Turns out that we had someone from their desktop connecting to the indexer pool and sending a bundle about 600MB every 5 minutes.

0 Karma

ShaneNewman
Motivator

They are about 100MB each.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...