We're using the docker images at https://hub.docker.com/r/splunk/splunk to install splunk in kubernetes. We're currently using 7.2.4, and are preparing to upgrade to 7.2.9.1.
The configuration stage (using splunk-ansible) of the search cluster is failing for at least the following versions:
7.2.9
7.3.3
The log for each of the search cluster members shows:
FAILED - RETRYING: Destructive sync search head
We have tested the following versions and found that they do not exhibit this behaviour, and deploy a working search cluster:
7.2.4
7.2.5
7.2.6
7.2.7
(7.2.8 is broken in a totally different way; all the containers die almost immediately with 'ERROR: Couldn't read "/opt/splunk/etc/splunk-launch.conf" ')
My question is - does anyone here have 7.2.9 or 7.3.3 working using the docker containers and with a search cluster, and can they please share the secret?
Thanks,
Rich
... View more