Getting Data In

Why am I getting "Error in JSON response: Unexpected EOF" while attempting to deploy shcluster-bundle?

mdsnmss
SplunkTrust
SplunkTrust

We recently upgraded our test environment from 6.4.2 to 6.5.2 and upon attempting to deploy a new search head cluster bundle (shcluster-bundle), we are getting the following error:

Error while deploying apps to first member: Error while fetching apps baseline on target=<shcluster-captain>: Error in JSON response: Unexpected EOF

The only thing that I believe has recently changed in the bundle was adding some database drivers to Splunk DB Connect to be deployed to the cluster. Any ideas what might be causing the unexpected end of file error?

0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

Turns out I'm an idiot. When specifying target for the shcluster-bundle I was using the web port 8000 and not 8089. Who would have thought using the right port would work.

............................................________
....................................,.-‘”...................``~.,
.............................,.-”...................................“-.,
.........................,/...............................................”:,
.....................,?......................................................\,
.................../...........................................................,}
................./......................................................,:`^`..}
.............../...................................................,:”........./
..............?.....__.........................................:`.........../
............./__.(.....“~-,_..............................,:`........../
.........../(_....”~,_........“~,_....................,:`........_/
..........{.._$;_......”=,_.......“-,_.......,.-~-,},.~”;/....}
...........((.....*~_.......”=-._......“;,,./`..../”............../
...,,,___.\`~,......“~.,....................`.....}............../
............(....`=-,,.......`........................(......;_,,-”
............/.`~,......`-...............................\....../\
.............\`~.*-,.....................................|,./.....\,__
,,_..........}.>-._\...................................|..............`=~-,
.....`=~-,_\_......`\,.................................\
...................`=~-,,.\,...............................\
................................`:,,...........................`\..............__
.....................................`=-,...................,%`>--==``
........................................_\..........._,-%.......`\
...................................,<`.._|_,-&``................`\

View solution in original post

mik3y
Path Finder

@mdsnmss wrote:

We recently upgraded our test environment from 6.4.2 to 6.5.2 and upon attempting to deploy a new search head cluster bundle (shcluster-bundle), we are getting the following error:

Error while deploying apps to first member: Error while fetching apps baseline on target=<shcluster-captain>: Error in JSON response: Unexpected EOF

The only thing that I believe has recently changed in the bundle was adding some database drivers to Splunk DB Connect to be deployed to the cluster. Any ideas what might be causing the unexpected end of file error?


I also got this error when upgrading from 9.0.0 to 9.0.2.

The problem however for me was as simple as restarting each search head. My apply bundle command was always referencing 8089.

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

Turns out I'm an idiot. When specifying target for the shcluster-bundle I was using the web port 8000 and not 8089. Who would have thought using the right port would work.

............................................________
....................................,.-‘”...................``~.,
.............................,.-”...................................“-.,
.........................,/...............................................”:,
.....................,?......................................................\,
.................../...........................................................,}
................./......................................................,:`^`..}
.............../...................................................,:”........./
..............?.....__.........................................:`.........../
............./__.(.....“~-,_..............................,:`........../
.........../(_....”~,_........“~,_....................,:`........_/
..........{.._$;_......”=,_.......“-,_.......,.-~-,},.~”;/....}
...........((.....*~_.......”=-._......“;,,./`..../”............../
...,,,___.\`~,......“~.,....................`.....}............../
............(....`=-,,.......`........................(......;_,,-”
............/.`~,......`-...............................\....../\
.............\`~.*-,.....................................|,./.....\,__
,,_..........}.>-._\...................................|..............`=~-,
.....`=~-,_\_......`\,.................................\
...................`=~-,,.\,...............................\
................................`:,,...........................`\..............__
.....................................`=-,...................,%`>--==``
........................................_\..........._,-%.......`\
...................................,<`.._|_,-&``................`\

kkrishnan_splun
Splunk Employee
Splunk Employee

Solved my problem too ! Thanks 🙂

0 Karma

RngFox
Explorer

same here XD facepalm

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...