Splunk Enterprise

DistributedPeerManager - Cannot determine a latest common bundle, search may be blocked Error on master node

vtalanki
Path Finder

Hi,

We have disabled [distributedSearch] in out splunk cluster's master and indexer nodes. With this we are seeing below issues

WARN in Master:

 

WARN  DistributedPeerManager - Cannot determine a latest common bundle, search may be blocked

 


ERROR in Indexers:

 

SearchPeerBundlesSetup - Cannot find bundles for search peer: <master_ip_node>

 


What we tried?

  1. Enabled dist search in master alone(not on indexers) - both issues are gone
  2. Enabled dist search on all indexers alone(not on master) - Can still see both the issues
  3. Made an update to one of the apps and did apply-bundle - This is successful without any issues

So the solution seems to be enabling dist search on master.  But wanted to get more insight into this.

  1. What does dist search mean on master and indexers?
  2. Does master node needs to have dist search enabled?
  3. In 'Cannot determine a latest common bundle' and 'Cannot find bundles for search peer' what does bundle mean here? I'm sure these are not knowledge bundles. 
  4. Why indexer is treating master as search peer? 
Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...

Event Series: Mastering AI Tokenomics and Splunk Agent Observability

Beyond the Black Box: Correlating AI Performance and Tokenomics with Splunk Agent Observability   As ...