Knowledge Management

6.1.3 issue with mounted Bundles

michael_herbert
Explorer

Following the upgrade from 6.1.1 to 6.1.3, we found that mounted bundles were having issues (configured using http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Configuremountedbundles). Our search head and indexers could not communicate to each other, with log entries like the following:

Search head:

08-14-2014 14:50:00.559 +0000 ERROR DistributedBundleReplicationManager - Unable to upload bundle to peer named splunk-indexerserver with uri=blah:8089.
08-14-2014 14:50:00.559 +0000 ERROR DistributedBundleReplicationManager - bundle size=1141MB, path=/opt/splunk/var/run/splunk-searchheadserver-1408027681.bundle, is too large for replication, max_size=1024MB. Check for any large unwanted files in $SPLUNK_HOME/etc/

Indexer:

08-14-2014 14:33:26.499 +0000 ERROR LMTracker - failed to send rows, reason='Unable to connect to remote peer: splunk-searchheadserver:8089 rc=2'

[will add answer separately]

0 Karma

michael_herbert
Explorer

With 6.1.1, we didn't have "shareBundles=false" set in the local distsearch.conf. With the upgrade to 6.1.3, the default distsearch.conf file adds "shareBundles=true" which was the problem. When we added "shareBundles=false" to our local conf file, it fixed the issue.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...