Getting Data In

Unexpected duplicate app: _cluster

aaronkorn
Splunk Employee
Splunk Employee

So we recently had clustering enabled in our environment and decided to remove it and now we keep getting the following error when starting our indexers: ERROR ApplicationManager - Unexpected duplicate app: _cluster. The indexer starts fine but what can I do to get rid of this message?

1 Solution

phemmer
Path Finder

Look in /opt/splunk/etc/apps for an entry called _cluster. Remove it and restart splunk. The error should go away.

In my case I had to do a little extra. I was messing around trying to get the shuttl app to work. I somehow managed to create some duplicate buckets in my _internal and _audit indexes. Until I fixed the duplicates, splunk kept re-creating that _cluster app (it was using that app to create a indexes.conf which disabled the _internal and _audit indexes) whenever I tried to remove it.

View solution in original post

phemmer
Path Finder

Look in /opt/splunk/etc/apps for an entry called _cluster. Remove it and restart splunk. The error should go away.

In my case I had to do a little extra. I was messing around trying to get the shuttl app to work. I somehow managed to create some duplicate buckets in my _internal and _audit indexes. Until I fixed the duplicates, splunk kept re-creating that _cluster app (it was using that app to create a indexes.conf which disabled the _internal and _audit indexes) whenever I tried to remove it.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...