Splunk Search

Why do we get a "Failed to create a bundles setup with server name GUID" message?

ddrillic
Ultra Champion

We get a message such as - *[indexer name] Failed to create a bundles setup with server name GUID : Using peer's local bundles to execute the search, results might not be correct. *

Search results seem to be much smaller than expected.

What can it be?

0 Karma

swatghare
Path Finder

I had this issue when I missed created configuration for one of the Search Head Cluster instance. I validate the configuration and checked on each Search Head if they have same Config about IDX cluster and this solves the project.

0 Karma

ronencoh
Engager

Had the same issue,

Restarting the SH solved it for me

Note: my configuration is 1 SH connected to 1 Indexer

Also, another similar question is this one

wanquan224
Engager

I also get this error after setup my SHC (Search head cluster). But after run the bundle command in the deployer, the error was gone. So, it maybe need to run the bundle command when you setup the SHC to sync the bundle in each SHC for the first time.

Bundle Command:
$~ bin/splunk apply shcluster-bundle -action stage --answer-yes
$~ bin/splunk apply shcluster-bundle -action send -target https://10.x.x.x:8089 --answer-yes

10.x.x.x : One of your SHC members.

0 Karma

ddrillic
Ultra Champion

We bounced this indexer, let's see...

A very similar issue at StreamedSearch - Failed to create a bundles setup with server name

@cpetterborg said back then -

-- I found the answer to my problem. A system administrator had mounted another NFS file system over the top of the shared data filesystem. This happened on two of our indexers, so access to the data under that mount point was being hidden.

Another one at SHC Showing errors with create bundle

0 Karma

ddrillic
Ultra Champion

Another message we see on a job says - Gave up waiting for the captain to establish a common bundle version across all search peers; using most recent bundles on all peers instead.

When running /opt/splunk/bin/splunk show shcluster-status all looks fine.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...