Splunk Search

Problem replicating config (bundle) to search peer

splunkcol
Builder

hi

can someone help me with this error message?

Sin título.jpg

will it be because of this file and its size? can i delete it?

Screenshot_3.png

Labels (1)
Tags (2)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

replicating 265 MB should not be a problem. 

can you check the connectivity of search peer in search head, settings -> Distributed search -> search peers.

is status healthy?

 

————————————
If this helps, give a like below.
0 Karma

splunkcol
Builder

Hi,

It is fine but I have seen it several times in "failed" state

It's even intermittent between "Successful" and "failed"

splunkcol_0-1598720885025.png

@thambisetty  what do you think is the cause?

0 Karma

splunkcol
Builder

Sorry for the insistence, could someone give me recommendations? 😭

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Did this happened regularly?

Which kind of environment you have?

Have you MC (monitoring console) in use so you could check what there happened.

r. Ismo

0 Karma

splunkcol
Builder

Did this happened regularly?
Yes

Which kind of environment you have?

2 Search Head
2 Indexers
2 Heavy Forwarder

I have access to the monitor, but there are several menus and submenu, which option should I check exactly?

Just as I investigated the problem is presented because the file called bundle is very heavy which causes the error message, my question at this time is if this bundle file can be debugged?

 

 

 

Tags (1)
0 Karma

splunkcol
Builder

hi @isoutamo 

I will read each thread and inform you.

Thank you

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...