Getting Data In

Error while creating new index

VijaySrrie
Builder

while trying to create a new index in search head getting error like Invalid apply cluster-bundle error="Bundle validation is in progress

Labels (1)
Tags (2)
0 Karma
1 Solution

VijaySrrie
Builder

Hi All,

As this is cloud we do not have access to modify indexes.conf. Splunk vendor team has done the necessary changes and a rolling restart performed. Now we are able to see the new index created

View solution in original post

0 Karma

VijaySrrie
Builder

Hi All,

As this is cloud we do not have access to modify indexes.conf. Splunk vendor team has done the necessary changes and a rolling restart performed. Now we are able to see the new index created

0 Karma

codebuilder
Influencer

This can happen when validation fails (for multiple reasons). If the indexes.conf your are trying to deploy has not changed, you'll never get a new bundle created. One workaround that I use for this issue is to simply modify indexes.conf, and a extra "space" to the file (so that it is different from previous version) and re-validate, then push it out again.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you create other indexes recently? If so, you must wait for that change to propagate to the rest of the search heads and indexers before creating another.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ivanreis
Builder

Are you working on an indexer cluster environment? I am asking because this error message is related with a cluster master issue when deploying a new bundle configuration.
If so, I would rollback the current configuration running this command from CLI
./splunk rollback cluster-bundle
Or using web - https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/Updatepeerconfigurations#Rollback_the_con....

Restart the cluster master and Indexer cluster and try to redeploy the bundle.

please check this document for further information- > https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/Updatepeerconfigurations

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The question is tagged with splunk-cloud so no CLI is available.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...