Splunk Search

Captain Skipping Configuration Replication

rafamss
Contributor

Hi guys,

I'm having a problem with my environment, we have 15 machines, 1 Master, 1 Deploy, 1 Universal Forwarder, 6 Search Head, 5 Indexers. The message below begin to appear in my search heads.

The search head cluster captain (https://server0011:8089) is disconnected; skipping configuration replication

We have replication factor of 1 to 3.

What can be ?

jkat54
SplunkTrust
SplunkTrust

This usually happens to me when the cluster master goes down for whatever reason.

Try running 'splunk status' on the captains command line. Then perhaps you'll fine a 'splunk start' is in order.

0 Karma

ben_leung
Builder

I would suggest looking at your conf.log for "data.worklog{}.status”=STOP_ON_MISSING_LOCAL_BASELINE

This would tell you if there are potential out of sync nodes from the clusters' captain. I see that these messages automatically disappear. Would that mean the node has dropped its captaincy and after re-synced to the new captains bundle?

0 Karma

jeremykampwerth
Engager

We are experiencing this issue. Any solution?

0 Karma

aalanisr26
Path Finder

we have the same problem did you find a solution?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...