Splunk Search

Large lookup files.

drussell88
Explorer

I am getting a warning in my splunkd.log for DistributedBundleReplicationManger.
03-15-2013 08:44:28.028 -0400 WARN DistributedBundleReplicationManager - bundle replication to 1 peer(s) took too long (29578ms), bundle file size=64480KB, replication_id=1363351438.
I read that this may be caused by a large look up file. What is this file they are talking about and where do I find it? I am getting this error about once a minute and it is always the same size, so I am assuming it is the same file.

Tags (1)
0 Karma

Strype
Path Finder

Are you looking for all lookup files?

Manager» Lookups» Lookup table files

Likely a csv file used in a search. The knowledge bundle can be found at Splunk Home>var>run>searchpeers>(latest).bundle (that is a file so replace > with backslash), on the search peer. It'll be in there along with every other one you have.

I'm having a similar problem except that mine is past the warn stage.

martin_mueller
SplunkTrust
SplunkTrust

Your bundle is 64MB, so I guess there is 63MB worth of lookup files somewhere in /lookups of some distributed app.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...