Deployment Architecture

"Encountered an error deserializing SearchResultsInfo from ResultsStream header." trying to search a Splunk 6.2.4 indexer cluster with a 6.1.5 search head

Lucas_K
Motivator

I have a Search head running Splunk 6.1.5 (can't currently upgrade) and it is trying to search an indexer cluster running on 6.2.4.

It errors out for these particular peers with the error:

08-12-2015 15:11:18.120 ERROR ResultsStream - Encountered an error deserializing SearchResultsInfo from ResultsStream header.

Checking the remote logs from the search peers and there are no errors at all. It's only on the search head.

I've tried readding the cluster master to the search head (removing it, restarting then adding it again) and I get the same issue.

1 Solution

Lucas_K
Motivator

Turns out that this is an unsupported configuration.

Documentation has been updated to reflect the supported version relationships between cluster master, search heads and indexers.

Info here : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Systemrequirements#Splunk_Enterprise_versi...

View solution in original post

Lucas_K
Motivator

Turns out that this is an unsupported configuration.

Documentation has been updated to reflect the supported version relationships between cluster master, search heads and indexers.

Info here : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Systemrequirements#Splunk_Enterprise_versi...

jeremiahc4
Builder

Getting the exact same error, but our search head and indexer are the same version. The search head member in our case is having difficulty getting the cluster config from the captain.

0 Karma

hzyyollow
New Member

We have encountered the same issue, search a Splunk indexer 6.3.3 and Splunk indexer 6.1.4 with a 6.1.4 search head. Is this a bug or configuration error?

0 Karma

vince2010091
Path Finder

same problem in 6.3.1

0 Karma

KarunK
Contributor

Same Problem as well on 6.3.1

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...