Splunk Enterprise

How to fix the Splunk enterprise bundle validation error in indexer nodes?

Vaidesh
New Member

Recently i upgraded our splunk enterprise version from 9.0.0 to 9.0.1 in all our master , search head & indexer nodes. The order we updated is indexer - search head - master. 

Once the upgrade was successfully done we weren't able to bring up the splunk cluster in which indexer node is keep on failing with the below mentioned error:

10-27-2022 23:02:27.083 +0000 ERROR CMSlave [91467 MainThread] - event=getActiveBundle failed with err="invalid active_bundle_id=.  Check the cluster manager for bundle validation/errors or other issues." even after multiple attempts, Exiting..
10-27-2022 23:02:27.106 +0000 ERROR loader [91467 MainThread] - Failed to download bundle from the cluster manager, err="invalid active_bundle_id=.  Check the cluster manager for bundle validation/errors or other issues.", Won't start splunkd. 

There are no errors in master & search head node's logs. Please help me to fix this bundle validation error.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

unfortunately you have had wrong update order and quite probably that has generated this issue. The correct order  MN, SH and latest indexers. To avoid more issues you should contact to splunk support if they have information how to fix this with more issues.

r. Ismo 

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...