nerdexam
Splunk

SPLK-2002(205Q) · Question #19

When adding or rejoining a member to a search head cluster, the following error is displayed: Error pulling configurations from the search head cluster captain; consider performing a destructive…

The correct answer is D. Run the splunk resync shcluster-replicated-config command on this member. When adding or rejoining a member to a search head cluster, and the following error is displayed: Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member. The corrective action…

Search Head Clustering

Question

When adding or rejoining a member to a search head cluster, the following error is displayed:

Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member. What corrective action should be taken?

Options

  • ARestart the search head.
  • BRun the splunk apply shcluster-bundle command from the deployer.
  • CRun the clean raft command on all members of the search head cluster.
  • DRun the splunk resync shcluster-replicated-config command on this member.

How the community answered

(23 responses)
  • A
    13% (3)
  • B
    4% (1)
  • C
    9% (2)
  • D
    74% (17)

Explanation

When adding or rejoining a member to a search head cluster, and the following error is displayed: Error pulling configurations from the search head cluster captain; consider performing a destructive configuration resync on this search head cluster member. The corrective action that should be taken is to run the splunk resync shcluster-replicated-config command on this member. This command will delete the existing configuration files on this member and replace them with the latest configuration files from the captain. This will ensure that the member has the same configuration as the rest of the cluster. Restarting the search head, running the splunk apply shcluster-bundle command from the deployer, or running the clean raft command on all members of the search head cluster are not the correct actions to take in this scenario. For more information, see Resolve configuration inconsistencies across cluster members in the Splunk

Topics

#search head cluster#configuration sync#SHC member resync#troubleshooting

Community Discussion

No community discussion yet for this question.

Full SPLK-2002(205Q) Practice