Deployment Architecture

bundle replication taking too long

EricPartington
Communicator

I have messages like the one below on a regular basis on my deployment server. Is there any way to determine what bundle is taking too long to replicate? Are there any other searches that will help me to determine which bundle to investigate?

10-05-2011 08:32:26.359 -0400 WARN DistributedBundleReplicationManager - bundle replication to 5 peer(s) took too long (18482ms), bundle file size=29110KB, replication_id=1317817927

1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Well, as of 4.1 and 4.2, there's only one bundle, and it's basically the entire contents of etc/apps, etc/system, and etc/users (with a limited set of exceptions). So pretty much, if you have something large anywhere in those locations (and I suspect it's a large lookup file) that's the cause.

To deal with this, you can either use network-mounted bundles (and disable replication), or see if asynchronous replication works for you. Both of these config options are available in 4.2 and up.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Well, as of 4.1 and 4.2, there's only one bundle, and it's basically the entire contents of etc/apps, etc/system, and etc/users (with a limited set of exceptions). So pretty much, if you have something large anywhere in those locations (and I suspect it's a large lookup file) that's the cause.

To deal with this, you can either use network-mounted bundles (and disable replication), or see if asynchronous replication works for you. Both of these config options are available in 4.2 and up.

dstaulcu
Builder

noticed that splunk app for windows had one such very large lookup files

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...