Deployment Architecture

Why am I getting "Unexpected duplicate app..." messages in an indexer cluster?

brent_weaver
Builder

Hey there... I have a Splunk environment with the following architecture:

1 Deployment Server
1 License Server
1 Index Cluster Master
4 Index Slaves/Cluster
3 node search head cluster
1 Search head not in the cluster

I keep getting the following message:

Unexpected duplicate app: cdop_all_indexer_base
        Checking filesystem compatibility...  Done
        Checking conf files for problems...
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
        Done
Unexpected duplicate app: cdop_all_indexer_base
        Checking replication_port port [8091]: Unexpected duplicate app: cdop_al                                                                                                                     l_indexer_base
open
Unexpected duplicate app: cdop_all_indexer_base
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Unexpected duplicate app: cdop_all_indexer_base
Done
                                                           [  OK  ]

It does look like these are duplicate apps:

indx2:/home/splunk $ find /opt/splunk/etc/ -name cdop_all_indexer_base
/opt/splunk/etc/slave-apps.old/cdop_all_indexer_base
/opt/splunk/etc/slave-apps/cdop_all_indexer_base
/opt/splunk/etc/apps/cdop_all_indexer_base
0 Karma
1 Solution

romiller
Engager

I was able to resolve this same issue by following the docs. In this particular app I was pushing the SSL config settings in the inputs.conf and the docs advises against that and states you will see this error because of this. I had to manually add the lines in that file to each indexer and remove the inputs.conf from the app and that fixed my issue. Hopefully this helps you as well.

http://docs.splunk.com/Documentation/Splunk/6.2.5/Indexer/Updatepeerconfigurations

View solution in original post

romiller
Engager

I was able to resolve this same issue by following the docs. In this particular app I was pushing the SSL config settings in the inputs.conf and the docs advises against that and states you will see this error because of this. I had to manually add the lines in that file to each indexer and remove the inputs.conf from the app and that fixed my issue. Hopefully this helps you as well.

http://docs.splunk.com/Documentation/Splunk/6.2.5/Indexer/Updatepeerconfigurations

romiller
Engager

I am also experiencing the same issue and my app is also similar to yours (i.e. all_indexer_base). Hopefully there is a resolution or a workaround for this.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...