Splunk Enterprise

DistributedPeerManager - Cannot determine a latest common bundle, search may be blocked Error on master node

vtalanki
Path Finder

Hi,

We have disabled [distributedSearch] in out splunk cluster's master and indexer nodes. With this we are seeing below issues

WARN in Master:

 

WARN  DistributedPeerManager - Cannot determine a latest common bundle, search may be blocked

 


ERROR in Indexers:

 

SearchPeerBundlesSetup - Cannot find bundles for search peer: <master_ip_node>

 


What we tried?

  1. Enabled dist search in master alone(not on indexers) - both issues are gone
  2. Enabled dist search on all indexers alone(not on master) - Can still see both the issues
  3. Made an update to one of the apps and did apply-bundle - This is successful without any issues

So the solution seems to be enabling dist search on master.  But wanted to get more insight into this.

  1. What does dist search mean on master and indexers?
  2. Does master node needs to have dist search enabled?
  3. In 'Cannot determine a latest common bundle' and 'Cannot find bundles for search peer' what does bundle mean here? I'm sure these are not knowledge bundles. 
  4. Why indexer is treating master as search peer? 
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...