Splunk Search

Why do we get a "Failed to create a bundles setup with server name GUID" message?

ddrillic
Ultra Champion

We get a message such as - *[indexer name] Failed to create a bundles setup with server name GUID : Using peer's local bundles to execute the search, results might not be correct. *

Search results seem to be much smaller than expected.

What can it be?

0 Karma

swatghare
Path Finder

I had this issue when I missed created configuration for one of the Search Head Cluster instance. I validate the configuration and checked on each Search Head if they have same Config about IDX cluster and this solves the project.

0 Karma

ronencoh
Engager

Had the same issue,

Restarting the SH solved it for me

Note: my configuration is 1 SH connected to 1 Indexer

Also, another similar question is this one

wanquan224
Engager

I also get this error after setup my SHC (Search head cluster). But after run the bundle command in the deployer, the error was gone. So, it maybe need to run the bundle command when you setup the SHC to sync the bundle in each SHC for the first time.

Bundle Command:
$~ bin/splunk apply shcluster-bundle -action stage --answer-yes
$~ bin/splunk apply shcluster-bundle -action send -target https://10.x.x.x:8089 --answer-yes

10.x.x.x : One of your SHC members.

0 Karma

ddrillic
Ultra Champion

We bounced this indexer, let's see...

A very similar issue at StreamedSearch - Failed to create a bundles setup with server name

@cpetterborg said back then -

-- I found the answer to my problem. A system administrator had mounted another NFS file system over the top of the shared data filesystem. This happened on two of our indexers, so access to the data under that mount point was being hidden.

Another one at SHC Showing errors with create bundle

0 Karma

ddrillic
Ultra Champion

Another message we see on a job says - Gave up waiting for the captain to establish a common bundle version across all search peers; using most recent bundles on all peers instead.

When running /opt/splunk/bin/splunk show shcluster-status all looks fine.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...