After running out of disk space on a search head (part of a cluster), now fixed and all SH's rebooted. I get this error: ConfReplicationException Error pulling configurations from the search head cluster captain (SH2:8089); Error in fetchFrom, at=: Non-200 status_code=500: refuse request without valid baseline; snapshot exists at op_id=xxxx6e8e for repo=SH2:8089". Search head cluster member (SH3:8089) is having trouble pulling configs from the captain (SH2:8089). xxxxx Consider performing a destructive configuration resync on this search head cluster member. Ran "splunk resync shcluster-replicated-config" and get this: ConfReplicationException : Error downloading snapshot: Non-200 status_code=400: Error opening snapshot_file' /opt/splunk/var/run/snapshot/174xxxxxxxx82aca.bundle: No such file or directory. In the snapshot folder there is nothing, sometimes a few files, they don't match the other search heads. 'splunk show bundle-replication-status' is all green and the same as the other 2 SH's. Is there a force resync switch? Really can't remove this SH and run 'clean all'. Thank you!
... View more