Getting Data In

Why is one search head no longer communicating with indexers? Getting error "failed_because_BUNDLE_DATA_TRANSMIT_FAILURE"

vr2312
Builder

We have around 10 Search Heads and 13 Indexers. Since this morning, we are seeing the below errors and our SH is not communicating with any of the Indexers associated.

All the other search heads are working as usual and have continuous communication to the Indexers.

05-23-2016 08:04:03.515 -0400 WARN  DistributedPeerManager - Unable to distribute to peer named XXX.YYY.ZZZ at uri https://XXX.YYY.ZZZ:8089 because replication was unsuccessful. replicationStatus Failed failure info: failed_because_BUNDLE_DATA_TRANSMIT_FAILURE
05-23-2016 08:04:03.515 -0400 WARN  DistributedPeerManager - Unable to distribute to peer named XXX.YYY.ZZZ at uri https://XXX.YYY.ZZZ:8089 because replication was unsuccessful. replicationStatus Failed failure info: failed_because_BUNDLE_DATA_TRANSMIT_FAILURE
05-23-2016 08:04:03.515 -0400 WARN  DistributedPeerManager - Unable to distribute to peer named XXX.YYY.ZZZ at uri https://XXX.YYY.ZZZ:8089 because replication was unsuccessful. replicationStatus Failed failure info: failed_because_BUNDLE_DATA_TRANSMIT_FAILURE
1 Solution

vr2312
Builder

I just sorted the stuff on my own. It was not due to the server.conf file.

I noticed a lot of ".csv" were being transmitted to the indexers from that SH. And that has taken a toll on it.

I went ahead and blacklisted the files and the apps that are being replicated unnecessarily.

Now it works just like old times.

Thank you for your response @jkat54

View solution in original post

twinspop
Influencer

I had the same issue. I upgraded to 6.5.3 from 6.5.1 last week. This is the first time I've seen it. Possibly related? Anyway, a restart of the single search head that was reporting the problem fixed it. For now. Alert in place to catch more.

0 Karma

vr2312
Builder

I just sorted the stuff on my own. It was not due to the server.conf file.

I noticed a lot of ".csv" were being transmitted to the indexers from that SH. And that has taken a toll on it.

I went ahead and blacklisted the files and the apps that are being replicated unnecessarily.

Now it works just like old times.

Thank you for your response @jkat54

jkat54
SplunkTrust
SplunkTrust

Please mark this as your answer... its ok to answer your own questions 😉

0 Karma

jkat54
SplunkTrust
SplunkTrust

Usually this is due to bad cluster password stored in pass4symmkey in server.conf.

0 Karma

twinspop
Influencer

Not the case here. A restart of the SH "fixed" it. No changes made.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...