Reporting

Cluster has only 0 peers (waiting for 2 peers to join the cluster)

hrithiktej
Communicator

Receiving as we had to redistribute the configuration to peers and took restart i think both peers took restart when cluster master was down and now we are getting this error Cluster has only 0 peers (waiting for 2 peers to join the cluster)

Please help

0 Karma
1 Solution

hrithiktej
Communicator

Support worked with me to resolve this. The first step always check splunkd.log

Here's our WebEx recap with support team:

From the cluster master the logs made it looks like a network issue but in fact, the indexers were not starting up correctly after a cluster bundle push. After a bundle is deployed, indexers will restart. The indexers were not able to delete the $SPLUNK_HOME/slave-apps.old folder since the contents were owned by another owner.

Resolution: Manually removed the $SPLUNK_HOME/slave-apps.old folder and restarted Splunk.

View solution in original post

0 Karma

hrithiktej
Communicator

Support worked with me to resolve this. The first step always check splunkd.log

Here's our WebEx recap with support team:

From the cluster master the logs made it looks like a network issue but in fact, the indexers were not starting up correctly after a cluster bundle push. After a bundle is deployed, indexers will restart. The indexers were not able to delete the $SPLUNK_HOME/slave-apps.old folder since the contents were owned by another owner.

Resolution: Manually removed the $SPLUNK_HOME/slave-apps.old folder and restarted Splunk.

0 Karma
Get Updates on the Splunk Community!

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...

New This Month - SLO Capabilities, APM Advanced Filtering & Usage Analytics Plus ...

More for SLO Management We’re continuing to expand the built-in SLO management experience in Splunk ...

Enterprise Security Content Update (ESCU) | New Releases

In June, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...