Splunk Search

Problem replicating config (bundle) to search peer

splunkcol
Builder

hi

can someone help me with this error message?

Sin título.jpg

will it be because of this file and its size? can i delete it?

Screenshot_3.png

Labels (1)
Tags (2)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

replicating 265 MB should not be a problem. 

can you check the connectivity of search peer in search head, settings -> Distributed search -> search peers.

is status healthy?

 

————————————
If this helps, give a like below.
0 Karma

splunkcol
Builder

Hi,

It is fine but I have seen it several times in "failed" state

It's even intermittent between "Successful" and "failed"

splunkcol_0-1598720885025.png

@thambisetty  what do you think is the cause?

0 Karma

splunkcol
Builder

Sorry for the insistence, could someone give me recommendations? 😭

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Did this happened regularly?

Which kind of environment you have?

Have you MC (monitoring console) in use so you could check what there happened.

r. Ismo

0 Karma

splunkcol
Builder

Did this happened regularly?
Yes

Which kind of environment you have?

2 Search Head
2 Indexers
2 Heavy Forwarder

I have access to the monitor, but there are several menus and submenu, which option should I check exactly?

Just as I investigated the problem is presented because the file called bundle is very heavy which causes the error message, my question at this time is if this bundle file can be debugged?

 

 

 

Tags (1)
0 Karma

splunkcol
Builder

hi @isoutamo 

I will read each thread and inform you.

Thank you

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...