Splunk Enterprise

DistributedPeerManager - Cannot determine a latest common bundle, search may be blocked Error on master node

vtalanki
Path Finder

Hi,

We have disabled [distributedSearch] in out splunk cluster's master and indexer nodes. With this we are seeing below issues

WARN in Master:

 

WARN  DistributedPeerManager - Cannot determine a latest common bundle, search may be blocked

 


ERROR in Indexers:

 

SearchPeerBundlesSetup - Cannot find bundles for search peer: <master_ip_node>

 


What we tried?

  1. Enabled dist search in master alone(not on indexers) - both issues are gone
  2. Enabled dist search on all indexers alone(not on master) - Can still see both the issues
  3. Made an update to one of the apps and did apply-bundle - This is successful without any issues

So the solution seems to be enabling dist search on master.  But wanted to get more insight into this.

  1. What does dist search mean on master and indexers?
  2. Does master node needs to have dist search enabled?
  3. In 'Cannot determine a latest common bundle' and 'Cannot find bundles for search peer' what does bundle mean here? I'm sure these are not knowledge bundles. 
  4. Why indexer is treating master as search peer? 
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...