Reporting

Cluster has only 0 peers (waiting for 2 peers to join the cluster)

hrithiktej
Communicator

Receiving as we had to redistribute the configuration to peers and took restart i think both peers took restart when cluster master was down and now we are getting this error Cluster has only 0 peers (waiting for 2 peers to join the cluster)

Please help

0 Karma
1 Solution

hrithiktej
Communicator

Support worked with me to resolve this. The first step always check splunkd.log

Here's our WebEx recap with support team:

From the cluster master the logs made it looks like a network issue but in fact, the indexers were not starting up correctly after a cluster bundle push. After a bundle is deployed, indexers will restart. The indexers were not able to delete the $SPLUNK_HOME/slave-apps.old folder since the contents were owned by another owner.

Resolution: Manually removed the $SPLUNK_HOME/slave-apps.old folder and restarted Splunk.

View solution in original post

0 Karma

hrithiktej
Communicator

Support worked with me to resolve this. The first step always check splunkd.log

Here's our WebEx recap with support team:

From the cluster master the logs made it looks like a network issue but in fact, the indexers were not starting up correctly after a cluster bundle push. After a bundle is deployed, indexers will restart. The indexers were not able to delete the $SPLUNK_HOME/slave-apps.old folder since the contents were owned by another owner.

Resolution: Manually removed the $SPLUNK_HOME/slave-apps.old folder and restarted Splunk.

0 Karma
Get Updates on the Splunk Community!

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...