<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer Discovery Error; pass4SymmKey or SSL? in Security</title>
    <link>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298972#M12693</link>
    <description>&lt;P&gt;I have already tried changing the indexer discovery password and rebooting. Why would I need to change "all passwords" when the forwarder only used the one indexer discovery password? Also, what do you mean by clearing the IP?&lt;/P&gt;</description>
    <pubDate>Tue, 20 Feb 2018 17:05:55 GMT</pubDate>
    <dc:creator>22isaiah</dc:creator>
    <dc:date>2018-02-20T17:05:55Z</dc:date>
    <item>
      <title>Indexer Discovery Error; pass4SymmKey or SSL?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298968#M12689</link>
      <description>&lt;P&gt;After setting the pass4SymmKey in my master node's server.conf file and in my forwarder's output.conf file I am still unable to make them communicate for indexer discovery. I made sure I typed the same key in both areas.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#server.conf on master indexer
[general]
serverName = splunk-indexer01
pass4SymmKey = $xxxxxxxxxxxx

[sslConfig]
sslPassword = $xxxxxxxxxxx

[clustering]
pass4SymmKey = $xxxxxxxxxxxxxxxxxxxxxxxxxxxx==
cluster_label = index_cluster
mode = master

[lmpool:auto_generated_pool_download-trial]
description = auto_generated_pool_download-trial
quota = MAX
slaves = *
stack_id = download-trial

[lmpool:auto_generated_pool_forwarder]
description = auto_generated_pool_forwarder
quota = MAX
slaves = *
stack_id = forwarder

[lmpool:auto_generated_pool_free]
description = auto_generated_pool_free
quota = MAX
slaves = *
stack_id = free

[indexer_discovery]
pass4SymmKey = $xxxxxxxxx=

#output.conf on forwarder
[indexer_discovery:splunk-indexer01]
pass4SymmKey = $xxxxxxxxx=
master_uri = &lt;A href="http://10.xxx.xxx.xxx:8089" target="test_blank"&gt;http://10.xxx.xxx.xxx:8089&lt;/A&gt;

[tcpout:my_indexers]
indexerDiscovery = splunk-indexer01

[tcpout]
defaultGroup = my_indexers

#errors
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Forwarders splunkd.log file&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;-0700 ERROR IndexerDiscoveryHeartbeatThread - Error in Indexer Discovery communication. Verify that the pass4SymmKey set under [indexer_discovery:my_indexers] in 'outputs.conf' matches the same setting  under [indexer_discovery] in 'server.conf' on the Cluster Master. [uri=http://10.xxx.xxx.xxx:8089/services/indexer_discovery http_code=502 http_response="Connection reset by peer"]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Master indexer's splunkd.log file&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;-0700 WARN  HttpListener - Socket error from 10.xxx.xxx.xx while idling: error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The IPs specified in the error's output are the correct IPs of the master indexer and forwarder, respectively, so they are trying to communicate. I am wondering if the SSL is the real culprit since my indexer discovery is set for tcp, but I'm not sure since I'm getting a pass4SymmKey error and I'm not sure how to solve either of these. Any help would be greatly appreciated. I'm using Splunk Enterprise 7.0.2. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 19:49:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298968#M12689</guid>
      <dc:creator>22isaiah</dc:creator>
      <dc:date>2018-02-19T19:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Discovery Error; pass4SymmKey or SSL?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298969#M12690</link>
      <description>&lt;P&gt;Just replaced all passwords with &lt;CODE&gt;something&lt;/CODE&gt; and cleared the IP. &lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 03:02:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298969#M12690</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-02-20T03:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Discovery Error; pass4SymmKey or SSL?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298970#M12691</link>
      <description>&lt;P&gt;Hey 22isaiah,&lt;/P&gt;

&lt;P&gt;The pass4SymmKey for clustering must be different to indexer_discovery. Try changing password for both stanzas and restart.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 05:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298970#M12691</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2018-02-20T05:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Discovery Error; pass4SymmKey or SSL?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298971#M12692</link>
      <description>&lt;P&gt;I set them different to begin with, you can see they are very different in length. Also, I tried changing the indexer discovery password multiple times and rebooting before posting here. I didn't change the cluster password however, because your forwarders don't use that anywhere. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 16:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298971#M12692</guid>
      <dc:creator>22isaiah</dc:creator>
      <dc:date>2018-02-20T16:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Discovery Error; pass4SymmKey or SSL?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298972#M12693</link>
      <description>&lt;P&gt;I have already tried changing the indexer discovery password and rebooting. Why would I need to change "all passwords" when the forwarder only used the one indexer discovery password? Also, what do you mean by clearing the IP?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 17:05:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298972#M12693</guid>
      <dc:creator>22isaiah</dc:creator>
      <dc:date>2018-02-20T17:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Discovery Error; pass4SymmKey or SSL?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298973#M12694</link>
      <description>&lt;P&gt;This was not an answer to your question: If you include your real encrypted password here, people are still able to decrypt them &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
That's why I changed/removed them from your post.&lt;/P&gt;

&lt;P&gt;Hope this makes sense ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 21:26:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298973#M12694</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-02-20T21:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Discovery Error; pass4SymmKey or SSL?</title>
      <link>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298974#M12695</link>
      <description>&lt;P&gt;Hi 22isaiah,&lt;/P&gt;

&lt;P&gt;but now you get an answer &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
According to the logs it's not related to your &lt;CODE&gt;pass4SymmKey&lt;/CODE&gt; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;You have this setting on the forwarder in &lt;CODE&gt;outputs.conf&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;master_uri = &lt;A href="http://10.130.154.112:8089" target="test_blank"&gt;http://10.130.154.112:8089&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but it should be &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;master_uri = &lt;A href="https://10.130.154.112:8089" target="test_blank"&gt;https://10.130.154.112:8089&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This is the reason the cluster master is complaining with this message:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;WARN  HttpListener - Socket error from 10.xxx.xxx.xx while idling: error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So the master is not even checking the &lt;CODE&gt;pass4Symmkey&lt;/CODE&gt; because the forwarder is not able to establish a proper connection.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2018 21:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Indexer-Discovery-Error-pass4SymmKey-or-SSL/m-p/298974#M12695</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-02-20T21:43:01Z</dc:date>
    </item>
  </channel>
</rss>

