Deployment Architecture

SHC Captain Disconnected

MFiller90
New Member

Hey Splunkers,

It seems that several times per hour that our SHC (of 9 SH's) seems to randomley disconnect the SHC Captain. We only ever see the "pumpkins" in the top on the search head GUIs. Something to the effect of "Search Head Captain disconnected blah blah"

The fun part is that, nothing actually bad happens. Our searches continue to run and complete. The errors eventually disappear after about 45 seconds. The annoying part is that if the timing is right, and you try to push a new bundle via Deployer --> SHC, the Deployer says "No captain found amongst members". To which, we just repush and it magically goes through just fine.

Running Splunk Enterprise v7.0.5

Has anybody ever seen anything similar to this?

Thanks!

Tags (2)
0 Karma

nareshinsvu
Builder

Might be network glitches? Do you see any errors in your splunkd.log?

For detail of troubleshooting, you might want to file a Support case with a splunk diag file so that Support engineer can take look into more detail.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...