Splunk Search

We see this error message "Search peer USADC-xxxxx has the following message: Too many streaming errors to target=xx.xx.xxx:8080.

shivanandbm
Explorer

We have four indexer and replication factor is 2.replication port is on all indexer is 8080 and is enabled on all server.
We observed that indexer 2 and indexer 4 has lost the connectivity and they were not able to ping each other but indexer 1 can ping indexer 4 and indexer 3 can ping indexer 4 vice versa.Not sure what is the exact issue. can some one suggest on this?

Below is the complete error message

"Search peer indexer4-xxxxx has the following message: Too many streaming errors to target=xx.2.70.xxx:8080. Not rolling hot buckets on further errors to this target. (This condition might exist with other targets too. Please check the logs)"

Tags (1)
0 Karma

nickhills
Ultra Champion

You noted in another question that this issue is resolved. Please add a note to say what you did and accept your own answer so others can see how you resolved it!

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

If you have transport failures (ie, you cant ping the hosts) this is not a Splunk problem.

You will need your network/ops team to diagnose the issue - could be any number of problems. Network config/firewalls/routing.

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...