Getting Data In

Bundle Replication Issue

ShaneNewman
Motivator

I have an indexer that seems to be having an issue keeping up with bundles with Splunk 5.0.5. I have been though S.O.S. looking for a cause, the only thing I see in the logs are timeouts waiting for the indexer to receive the bundle. There are 4 servers that maintain bundles with this indexer. This indexer is connected via fiber (10G).

Anyone have any ideas what is going on or where I could look to get more insight into this problem?

0 Karma
1 Solution

adityapavan18
Contributor

Shane, how big are the bundle files?

You can refer this

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch#Limit_the_knowledg...

And see if the smaller bundles are being pushed without a timeout

View solution in original post

adityapavan18
Contributor

Shane, how big are the bundle files?

You can refer this

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch#Limit_the_knowledg...

And see if the smaller bundles are being pushed without a timeout

ShaneNewman
Motivator

I found the issue after getting into the searchpeers folder. Turns out that we had someone from their desktop connecting to the indexer pool and sending a bundle about 600MB every 5 minutes.

0 Karma

ShaneNewman
Motivator

They are about 100MB each.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...