I have a Splunk indexer cluster with these parameters:
1 Master node
1 Search Head node
RF = 2, SF = 2, both don't respected
For several days, and in this moment, with a real-time search on _internal index, I see on the first Indexer many sequences of these type of errors. The other indexer doesn't have the same problem.
ERROR TcpInputProc - event=replicationData status=failed err=
ERROR S2SFileReceiver - event=rename replicationType=eJournalReplication status=failed err=Rename failed in 1 attempt(s) made between status code: 17
Which can be the cause of this behavior?
it is most likely happening because of corrupted buckets, you can see them in cluster master webpage as well. to fix the issue you need to remove them. please see how to remove bucket in this post
@Vaianna: Check this post https://answers.splunk.com/answers/295363/why-am-i-getting-error-s2sfilereceiver-eventstatsi.html
There are few of the checklist available to validate. If you have found the root cause share it..