Splunk Search

We see this error message "Search peer USADC-xxxxx has the following message: Too many streaming errors to target=xx.xx.xxx:8080.

shivanandbm
Explorer

We have four indexer and replication factor is 2.replication port is on all indexer is 8080 and is enabled on all server.
We observed that indexer 2 and indexer 4 has lost the connectivity and they were not able to ping each other but indexer 1 can ping indexer 4 and indexer 3 can ping indexer 4 vice versa.Not sure what is the exact issue. can some one suggest on this?

Below is the complete error message

"Search peer indexer4-xxxxx has the following message: Too many streaming errors to target=xx.2.70.xxx:8080. Not rolling hot buckets on further errors to this target. (This condition might exist with other targets too. Please check the logs)"

Tags (1)
0 Karma

nickhills
Ultra Champion

You noted in another question that this issue is resolved. Please add a note to say what you did and accept your own answer so others can see how you resolved it!

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

If you have transport failures (ie, you cant ping the hosts) this is not a Splunk problem.

You will need your network/ops team to diagnose the issue - could be any number of problems. Network config/firewalls/routing.

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...