Splunk Search

Problem replicating config (bundle) to search peer

splunkcol
Builder

hi

can someone help me with this error message?

Sin título.jpg

will it be because of this file and its size? can i delete it?

Screenshot_3.png

Labels (2)
Tags (2)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

replicating 265 MB should not be a problem. 

can you check the connectivity of search peer in search head, settings -> Distributed search -> search peers.

is status healthy?

 

————————————
If this helps, give a like below.
0 Karma

splunkcol
Builder

Hi,

It is fine but I have seen it several times in "failed" state

It's even intermittent between "Successful" and "failed"

splunkcol_0-1598720885025.png

@thambisetty  what do you think is the cause?

0 Karma

splunkcol
Builder

Sorry for the insistence, could someone give me recommendations? 😭

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Did this happened regularly?

Which kind of environment you have?

Have you MC (monitoring console) in use so you could check what there happened.

r. Ismo

0 Karma

splunkcol
Builder

Did this happened regularly?
Yes

Which kind of environment you have?

2 Search Head
2 Indexers
2 Heavy Forwarder

I have access to the monitor, but there are several menus and submenu, which option should I check exactly?

Just as I investigated the problem is presented because the file called bundle is very heavy which causes the error message, my question at this time is if this bundle file can be debugged?

 

 

 

Tags (1)
0 Karma

splunkcol
Builder

hi @isoutamo 

I will read each thread and inform you.

Thank you

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...