Getting Data In

Unexpected duplicate app: _cluster

aaronkorn
Splunk Employee
Splunk Employee

So we recently had clustering enabled in our environment and decided to remove it and now we keep getting the following error when starting our indexers: ERROR ApplicationManager - Unexpected duplicate app: _cluster. The indexer starts fine but what can I do to get rid of this message?

1 Solution

phemmer
Path Finder

Look in /opt/splunk/etc/apps for an entry called _cluster. Remove it and restart splunk. The error should go away.

In my case I had to do a little extra. I was messing around trying to get the shuttl app to work. I somehow managed to create some duplicate buckets in my _internal and _audit indexes. Until I fixed the duplicates, splunk kept re-creating that _cluster app (it was using that app to create a indexes.conf which disabled the _internal and _audit indexes) whenever I tried to remove it.

View solution in original post

phemmer
Path Finder

Look in /opt/splunk/etc/apps for an entry called _cluster. Remove it and restart splunk. The error should go away.

In my case I had to do a little extra. I was messing around trying to get the shuttl app to work. I somehow managed to create some duplicate buckets in my _internal and _audit indexes. Until I fixed the duplicates, splunk kept re-creating that _cluster app (it was using that app to create a indexes.conf which disabled the _internal and _audit indexes) whenever I tried to remove it.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...