Getting Data In

Why am I getting "Error in JSON response: Unexpected EOF" while attempting to deploy shcluster-bundle?

mdsnmss
SplunkTrust
SplunkTrust

We recently upgraded our test environment from 6.4.2 to 6.5.2 and upon attempting to deploy a new search head cluster bundle (shcluster-bundle), we are getting the following error:

Error while deploying apps to first member: Error while fetching apps baseline on target=<shcluster-captain>: Error in JSON response: Unexpected EOF

The only thing that I believe has recently changed in the bundle was adding some database drivers to Splunk DB Connect to be deployed to the cluster. Any ideas what might be causing the unexpected end of file error?

0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

Turns out I'm an idiot. When specifying target for the shcluster-bundle I was using the web port 8000 and not 8089. Who would have thought using the right port would work.

............................................________
....................................,.-‘”...................``~.,
.............................,.-”...................................“-.,
.........................,/...............................................”:,
.....................,?......................................................\,
.................../...........................................................,}
................./......................................................,:`^`..}
.............../...................................................,:”........./
..............?.....__.........................................:`.........../
............./__.(.....“~-,_..............................,:`........../
.........../(_....”~,_........“~,_....................,:`........_/
..........{.._$;_......”=,_.......“-,_.......,.-~-,},.~”;/....}
...........((.....*~_.......”=-._......“;,,./`..../”............../
...,,,___.\`~,......“~.,....................`.....}............../
............(....`=-,,.......`........................(......;_,,-”
............/.`~,......`-...............................\....../\
.............\`~.*-,.....................................|,./.....\,__
,,_..........}.>-._\...................................|..............`=~-,
.....`=~-,_\_......`\,.................................\
...................`=~-,,.\,...............................\
................................`:,,...........................`\..............__
.....................................`=-,...................,%`>--==``
........................................_\..........._,-%.......`\
...................................,<`.._|_,-&``................`\

View solution in original post

mik3y
Path Finder

@mdsnmss wrote:

We recently upgraded our test environment from 6.4.2 to 6.5.2 and upon attempting to deploy a new search head cluster bundle (shcluster-bundle), we are getting the following error:

Error while deploying apps to first member: Error while fetching apps baseline on target=<shcluster-captain>: Error in JSON response: Unexpected EOF

The only thing that I believe has recently changed in the bundle was adding some database drivers to Splunk DB Connect to be deployed to the cluster. Any ideas what might be causing the unexpected end of file error?


I also got this error when upgrading from 9.0.0 to 9.0.2.

The problem however for me was as simple as restarting each search head. My apply bundle command was always referencing 8089.

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

Turns out I'm an idiot. When specifying target for the shcluster-bundle I was using the web port 8000 and not 8089. Who would have thought using the right port would work.

............................................________
....................................,.-‘”...................``~.,
.............................,.-”...................................“-.,
.........................,/...............................................”:,
.....................,?......................................................\,
.................../...........................................................,}
................./......................................................,:`^`..}
.............../...................................................,:”........./
..............?.....__.........................................:`.........../
............./__.(.....“~-,_..............................,:`........../
.........../(_....”~,_........“~,_....................,:`........_/
..........{.._$;_......”=,_.......“-,_.......,.-~-,},.~”;/....}
...........((.....*~_.......”=-._......“;,,./`..../”............../
...,,,___.\`~,......“~.,....................`.....}............../
............(....`=-,,.......`........................(......;_,,-”
............/.`~,......`-...............................\....../\
.............\`~.*-,.....................................|,./.....\,__
,,_..........}.>-._\...................................|..............`=~-,
.....`=~-,_\_......`\,.................................\
...................`=~-,,.\,...............................\
................................`:,,...........................`\..............__
.....................................`=-,...................,%`>--==``
........................................_\..........._,-%.......`\
...................................,<`.._|_,-&``................`\

kkrishnan_splun
Splunk Employee
Splunk Employee

Solved my problem too ! Thanks 🙂

0 Karma

RngFox
Explorer

same here XD facepalm

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...