Getting Data In

Why am I getting "Error in JSON response: Unexpected EOF" while attempting to deploy shcluster-bundle?

mdsnmss
SplunkTrust
SplunkTrust

We recently upgraded our test environment from 6.4.2 to 6.5.2 and upon attempting to deploy a new search head cluster bundle (shcluster-bundle), we are getting the following error:

Error while deploying apps to first member: Error while fetching apps baseline on target=<shcluster-captain>: Error in JSON response: Unexpected EOF

The only thing that I believe has recently changed in the bundle was adding some database drivers to Splunk DB Connect to be deployed to the cluster. Any ideas what might be causing the unexpected end of file error?

0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

Turns out I'm an idiot. When specifying target for the shcluster-bundle I was using the web port 8000 and not 8089. Who would have thought using the right port would work.

............................................________
....................................,.-‘”...................``~.,
.............................,.-”...................................“-.,
.........................,/...............................................”:,
.....................,?......................................................\,
.................../...........................................................,}
................./......................................................,:`^`..}
.............../...................................................,:”........./
..............?.....__.........................................:`.........../
............./__.(.....“~-,_..............................,:`........../
.........../(_....”~,_........“~,_....................,:`........_/
..........{.._$;_......”=,_.......“-,_.......,.-~-,},.~”;/....}
...........((.....*~_.......”=-._......“;,,./`..../”............../
...,,,___.\`~,......“~.,....................`.....}............../
............(....`=-,,.......`........................(......;_,,-”
............/.`~,......`-...............................\....../\
.............\`~.*-,.....................................|,./.....\,__
,,_..........}.>-._\...................................|..............`=~-,
.....`=~-,_\_......`\,.................................\
...................`=~-,,.\,...............................\
................................`:,,...........................`\..............__
.....................................`=-,...................,%`>--==``
........................................_\..........._,-%.......`\
...................................,<`.._|_,-&``................`\

View solution in original post

mik3y
Path Finder

@mdsnmss wrote:

We recently upgraded our test environment from 6.4.2 to 6.5.2 and upon attempting to deploy a new search head cluster bundle (shcluster-bundle), we are getting the following error:

Error while deploying apps to first member: Error while fetching apps baseline on target=<shcluster-captain>: Error in JSON response: Unexpected EOF

The only thing that I believe has recently changed in the bundle was adding some database drivers to Splunk DB Connect to be deployed to the cluster. Any ideas what might be causing the unexpected end of file error?


I also got this error when upgrading from 9.0.0 to 9.0.2.

The problem however for me was as simple as restarting each search head. My apply bundle command was always referencing 8089.

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

Turns out I'm an idiot. When specifying target for the shcluster-bundle I was using the web port 8000 and not 8089. Who would have thought using the right port would work.

............................................________
....................................,.-‘”...................``~.,
.............................,.-”...................................“-.,
.........................,/...............................................”:,
.....................,?......................................................\,
.................../...........................................................,}
................./......................................................,:`^`..}
.............../...................................................,:”........./
..............?.....__.........................................:`.........../
............./__.(.....“~-,_..............................,:`........../
.........../(_....”~,_........“~,_....................,:`........_/
..........{.._$;_......”=,_.......“-,_.......,.-~-,},.~”;/....}
...........((.....*~_.......”=-._......“;,,./`..../”............../
...,,,___.\`~,......“~.,....................`.....}............../
............(....`=-,,.......`........................(......;_,,-”
............/.`~,......`-...............................\....../\
.............\`~.*-,.....................................|,./.....\,__
,,_..........}.>-._\...................................|..............`=~-,
.....`=~-,_\_......`\,.................................\
...................`=~-,,.\,...............................\
................................`:,,...........................`\..............__
.....................................`=-,...................,%`>--==``
........................................_\..........._,-%.......`\
...................................,<`.._|_,-&``................`\

kkrishnan_splun
Splunk Employee
Splunk Employee

Solved my problem too ! Thanks 🙂

0 Karma

RngFox
Explorer

same here XD facepalm

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...