Splunk Search

Search results might be incomplete: the search process on the peer

splunkcol
Builder

After spending two days reading almost all forum posts related to this error message, including translating questions from Chinese to Spanish, I finally found the cause of this error message:

Error message

  • Search results might be incomplete: the search process on the peer:indexador1 ended prematurely. Check the peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search.
  • Search results might be incomplete: the search process on the peer:indexador2 ended prematurely. Check the peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search.
  • [indexador1] Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.
  • [indexador2] Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.

 

cause 

If you want to setup a trial Splunk Enterprise distributed deployment consisting of multiple Splunk Enterprise instances communicating with each other, each instance must use its own self-generated Enterprise Trial license. This differs from a distributed deployment running a Splunk Enterprise license, where you will configure a license master to host all licenses."


https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/TypesofSplunklicenses

Labels (3)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

That’s true. You cannot use trial license in distributed LM, but you can use it on all nodes when you are doing distributed test setup.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

That’s true. You cannot use trial license in distributed LM, but you can use it on all nodes when you are doing distributed test setup.

r. Ismo

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...