Splunk Search

Unknown Root Cause of Error

JHFRDANALYSIS
Engager

Error in my results query:  Unable to distribute to peer named 10.245.11.153 at uri=10.245.11.153:8089 using the uri-scheme=https because peer has status=Down.   

My query doesn't request anything for URI to be checked or returned so I don't know the root cause.  

I need to get a clean output with an error.  Any suggestions how to fix this?


Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Almost every search request is sent to your indexers and those indexers each have a uri.  This error message is generated when Splunk is no longer able to communicate with one of the indexers.  It could be because the indexer is down or because a network error prevents communication with it.  Verify all indexers are running and the search head can connect to them all.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...