Splunk Search

Search results might be incomplete: the search process on the peer

splunkcol
Builder

After spending two days reading almost all forum posts related to this error message, including translating questions from Chinese to Spanish, I finally found the cause of this error message:

Error message

  • Search results might be incomplete: the search process on the peer:indexador1 ended prematurely. Check the peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search.
  • Search results might be incomplete: the search process on the peer:indexador2 ended prematurely. Check the peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search.
  • [indexador1] Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.
  • [indexador2] Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.

 

cause 

If you want to setup a trial Splunk Enterprise distributed deployment consisting of multiple Splunk Enterprise instances communicating with each other, each instance must use its own self-generated Enterprise Trial license. This differs from a distributed deployment running a Splunk Enterprise license, where you will configure a license master to host all licenses."


https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/TypesofSplunklicenses

Labels (3)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

That’s true. You cannot use trial license in distributed LM, but you can use it on all nodes when you are doing distributed test setup.

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

That’s true. You cannot use trial license in distributed LM, but you can use it on all nodes when you are doing distributed test setup.

r. Ismo

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...