Getting Data In

Bundle Replication Issue

ShaneNewman
Motivator

I have an indexer that seems to be having an issue keeping up with bundles with Splunk 5.0.5. I have been though S.O.S. looking for a cause, the only thing I see in the logs are timeouts waiting for the indexer to receive the bundle. There are 4 servers that maintain bundles with this indexer. This indexer is connected via fiber (10G).

Anyone have any ideas what is going on or where I could look to get more insight into this problem?

0 Karma
1 Solution

adityapavan18
Contributor

Shane, how big are the bundle files?

You can refer this

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch#Limit_the_knowledg...

And see if the smaller bundles are being pushed without a timeout

View solution in original post

adityapavan18
Contributor

Shane, how big are the bundle files?

You can refer this

http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch#Limit_the_knowledg...

And see if the smaller bundles are being pushed without a timeout

ShaneNewman
Motivator

I found the issue after getting into the searchpeers folder. Turns out that we had someone from their desktop connecting to the indexer pool and sending a bundle about 600MB every 5 minutes.

0 Karma

ShaneNewman
Motivator

They are about 100MB each.

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...