Hi,
I have a Splunk indexer cluster with these parameters:
1 Master node
1 Search Head node
2 Indexers
2 Forwarders
RF = 2, SF = 2, both don't respected
For several days, and in this moment, with a real-time search on _internal index, I see on the first Indexer many sequences of these type of errors. The other indexer doesn't have the same problem.
ERROR TcpInputProc - event=replicationData status=failed err=
ERROR S2SFileReceiver - event=rename replicationType=eJournalReplication status=failed err=Rename failed in 1 attempt(s) made between status code: 17
Which can be the cause of this behavior?
Thanks,
... View more