Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Unable to run searches in Splunk Enterprise Security because of the error "BUNDLE_SIZE_EXCEEDS_MAX_SIZE"

$
0
0
I am getting the following error in the Search Head running Splunk Enterprise Security: Unable to distribute to peer named splunk_1 at uri https://x.x.x.x:8089 because replication was unsuccessful. replicationStatus Failed failure info: failed_because_BUNDLE_SIZE_EXCEEDS_MAX_SIZE Please verify connectivity to the search peer, that the search peer is up, and an adequate level of system resources are available. See the Troubleshooting Manual for more information. I did some changes to distsearch.conf file, but the bundle is still over 3 GB in size. This is the file stanza: [replicationSettings] maxBundleSize = 4096 [replicationSettings] sendRcvTimeout = 1060 [replicationWhitelist] allConf = *.conf allSpec = *.spec [replicationSettings:refineConf] replicate.app = false replicate.authorize = true replicate.collections = false replicate.commands = false replicate.eventtypes = false replicate.fields = false replicate.segmenters = false replicate.literals = false replicate.lookups = false replicate.multikv = false replicate.props = true replicate.tags = true replicate.transforms = true replicate.transactiontypes = false [replicationBlacklist] nopyc = apps[/\\]...[/\\](bin|contrib|lib)[/\\]*.py[co] nopyc2 = apps[/\\]...[/\\](bin|contrib|lib)[/\\]...[/\\]*.py[co] nocsvdefault = apps[/\\]...[/\\]lookups[/\\]*.csv.default nolearned = apps[/\\]learned[/\\]... notracker = apps[/\\]...[/\\]lookups[/\\]*tracker.csv notracker2 = apps[/\\]...[/\\]lookups[/\\]*tracker2.csv nosigref = apps[/\\]...[/\\]lookups[/\\]*signature_reference.csv nosigref2 = apps[/\\]...[/\\]lookups[/\\]*signature_reference2.csv noeditablelookups = apps[/\\]...[/\\]lookups[/\\]editable_lookups.csv nolegacycontexts = apps[/\\]...[/\\]contexts[/\\]*.context noconvertedcontexts = apps[/\\]...[/\\]lookups[/\\]*.context.csv.old noinstallsrc = apps[/\\]SplunkEnterpriseSecuritySuite[/\\]@installsrc@[/\\]... lookupindexfiles = (system|apps/*|users(/_reserved)?/*/*)/lookups/*.(tmp$|index($|/...)) sampleapp = apps/sample_app/... conf = (system|(apps/*))/(default|local)/server.conf user_specific_meta = users(/_reserved)?/*/*/metadata/local.meta framework = apps/framework/...

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>