Splunk Search

Unknown Root Cause of Error

JHFRDANALYSIS
Engager

Error in my results query:  Unable to distribute to peer named 10.245.11.153 at uri=10.245.11.153:8089 using the uri-scheme=https because peer has status=Down.   

My query doesn't request anything for URI to be checked or returned so I don't know the root cause.  

I need to get a clean output with an error.  Any suggestions how to fix this?


Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Almost every search request is sent to your indexers and those indexers each have a uri.  This error message is generated when Splunk is no longer able to communicate with one of the indexers.  It could be because the indexer is down or because a network error prevents communication with it.  Verify all indexers are running and the search head can connect to them all.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...