Splunk Search

Why do we get a "Failed to create a bundles setup with server name GUID" message?

ddrillic
Ultra Champion

We get a message such as - *[indexer name] Failed to create a bundles setup with server name GUID : Using peer's local bundles to execute the search, results might not be correct. *

Search results seem to be much smaller than expected.

What can it be?

0 Karma

swatghare
Path Finder

I had this issue when I missed created configuration for one of the Search Head Cluster instance. I validate the configuration and checked on each Search Head if they have same Config about IDX cluster and this solves the project.

0 Karma

ronencoh
Engager

Had the same issue,

Restarting the SH solved it for me

Note: my configuration is 1 SH connected to 1 Indexer

Also, another similar question is this one

wanquan224
Engager

I also get this error after setup my SHC (Search head cluster). But after run the bundle command in the deployer, the error was gone. So, it maybe need to run the bundle command when you setup the SHC to sync the bundle in each SHC for the first time.

Bundle Command:
$~ bin/splunk apply shcluster-bundle -action stage --answer-yes
$~ bin/splunk apply shcluster-bundle -action send -target https://10.x.x.x:8089 --answer-yes

10.x.x.x : One of your SHC members.

0 Karma

ddrillic
Ultra Champion

We bounced this indexer, let's see...

A very similar issue at StreamedSearch - Failed to create a bundles setup with server name

@cpetterborg said back then -

-- I found the answer to my problem. A system administrator had mounted another NFS file system over the top of the shared data filesystem. This happened on two of our indexers, so access to the data under that mount point was being hidden.

Another one at SHC Showing errors with create bundle

0 Karma

ddrillic
Ultra Champion

Another message we see on a job says - Gave up waiting for the captain to establish a common bundle version across all search peers; using most recent bundles on all peers instead.

When running /opt/splunk/bin/splunk show shcluster-status all looks fine.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...