Splunk Search

Problem replicating config (bundle) to search peer

splunkcol
Builder

hi

can someone help me with this error message?

Sin título.jpg

will it be because of this file and its size? can i delete it?

Screenshot_3.png

Labels (2)
Tags (2)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

replicating 265 MB should not be a problem. 

can you check the connectivity of search peer in search head, settings -> Distributed search -> search peers.

is status healthy?

 

————————————
If this helps, give a like below.
0 Karma

splunkcol
Builder

Hi,

It is fine but I have seen it several times in "failed" state

It's even intermittent between "Successful" and "failed"

splunkcol_0-1598720885025.png

@thambisetty  what do you think is the cause?

0 Karma

splunkcol
Builder

Sorry for the insistence, could someone give me recommendations? 😭

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Did this happened regularly?

Which kind of environment you have?

Have you MC (monitoring console) in use so you could check what there happened.

r. Ismo

0 Karma

splunkcol
Builder

Did this happened regularly?
Yes

Which kind of environment you have?

2 Search Head
2 Indexers
2 Heavy Forwarder

I have access to the monitor, but there are several menus and submenu, which option should I check exactly?

Just as I investigated the problem is presented because the file called bundle is very heavy which causes the error message, my question at this time is if this bundle file can be debugged?

 

 

 

Tags (1)
0 Karma

splunkcol
Builder

hi @isoutamo 

I will read each thread and inform you.

Thank you

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...