<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring Console not functional after pass4SymmKey update (v9.0.2) in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Monitoring-Console-not-functional-after-pass4SymmKey-update-v9-0/m-p/622116#M14613</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;. I'm very confident on the consistency of the key, I checked it thoroughly and deliberately and performed a &lt;FONT face="courier new,courier"&gt;./splunk show-decrypted --value '&amp;lt;string&amp;gt;'&lt;/FONT&gt; on each node in each stanza. I will try the suggestion of deleting and re-adding all search peers on the MC with a reload.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Nov 2022 15:13:44 GMT</pubDate>
    <dc:creator>NullZero</dc:creator>
    <dc:date>2022-11-25T15:13:44Z</dc:date>
    <item>
      <title>Monitoring Console not functional after pass4SymmKey update (v9.0.2)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Monitoring-Console-not-functional-after-pass4SymmKey-update-v9-0/m-p/622088#M14610</link>
      <description>&lt;P&gt;I'm a Splunk PS consultant and have been assisting a client with upgrades and migration to SVA compliant architecture (C1). All well and fully operational on 9.0.2 and the client is happy with this improved and fully compliant deployment.&lt;/P&gt;&lt;P&gt;Following up from the works we reviewed what sensible security hardening could be implemented across the deployment and we agreed that the pass4SymmKey for the clustering stanza could be longer and more complex. We followed the docs and went to each instances' &lt;FONT face="courier new,courier"&gt;$SPLUNK_HOME/etc/system/local/server.conf&lt;/FONT&gt; and updated the key in plain text. We restarted the Splunkd daemon via Systemd on all instances and checked the infra. All functional and the cluster remains operating properly, ingesting data, clustering operations correct.&lt;/P&gt;&lt;P&gt;However... there is one flaw and that is the MC. That is no longer able to properly query the cluster, it has the DS on it as well and that is properly working and serving apps to clients. It has all the search parameters correct and all nodes listed and was functional immediately before rotation. Yes, I checked btool for the values on disk and decrypted it, all appears fine. After an hour of troubleshooting and checking spkunkd.log there was still no clue but we thought perhaps we had gone too complex on the string with special characters.&lt;/P&gt;&lt;P&gt;Rinse and repeat updating all cluster nodes pass4SymmKey to something less complex without special chars. Still failed to operate properly and we spent another hour very carefully reviewing every stanza in operation and consistency. We then decided to try and setup an MC on another node to compare, same exact issue and all checks just come back as greyed out.&lt;/P&gt;&lt;P&gt;Time pushing on we decided to revert to the original pass4SymmKey and restart daemon, guess what, still not working. We moved onto other pressing matters but I do not want to leave my client without an answer or approach medium term.&lt;/P&gt;&lt;P&gt;Potential for a bug? niche operation rotating pass4SymmKey?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 12:11:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Monitoring-Console-not-functional-after-pass4SymmKey-update-v9-0/m-p/622088#M14610</guid>
      <dc:creator>NullZero</dc:creator>
      <dc:date>2022-11-25T12:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Console not functional after pass4SymmKey update (v9.0.2)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Monitoring-Console-not-functional-after-pass4SymmKey-update-v9-0/m-p/622106#M14611</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;your are absolutely sure that you have update clustering stanza on DS too, not general (or others)? Have you try 1st remove cluster manager node (search peer) configuration from DS and then add it again with new key?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 14:10:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Monitoring-Console-not-functional-after-pass4SymmKey-update-v9-0/m-p/622106#M14611</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-11-25T14:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Console not functional after pass4SymmKey update (v9.0.2)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Monitoring-Console-not-functional-after-pass4SymmKey-update-v9-0/m-p/622116#M14613</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;. I'm very confident on the consistency of the key, I checked it thoroughly and deliberately and performed a &lt;FONT face="courier new,courier"&gt;./splunk show-decrypted --value '&amp;lt;string&amp;gt;'&lt;/FONT&gt; on each node in each stanza. I will try the suggestion of deleting and re-adding all search peers on the MC with a reload.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 15:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Monitoring-Console-not-functional-after-pass4SymmKey-update-v9-0/m-p/622116#M14613</guid>
      <dc:creator>NullZero</dc:creator>
      <dc:date>2022-11-25T15:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring Console not functional after pass4SymmKey update (v9.0.2)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Monitoring-Console-not-functional-after-pass4SymmKey-update-v9-0/m-p/627515#M15141</link>
      <description>&lt;P&gt;Apologies for the delayed response&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp; and resolution, I have only just been back to my client. This is now resolved.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We did try deleting a re-adding the distributed search peers, no luck. I did this previously as well.&lt;/LI&gt;&lt;LI&gt;I did re-check on fresh eyes the btool decrypted key in the cluster stanza, all good.&lt;/LI&gt;&lt;LI&gt;I even copied across a tar copy of the MC app and checked the manifest lookup file.&lt;/LI&gt;&lt;LI&gt;Some time expended, eager not to waste time went for the following approach&lt;/LI&gt;&lt;LI&gt;Built a fresh VM image to Splunk standards, I added the search peers in the UI.&lt;/LI&gt;&lt;LI&gt;The MC worked immediately and no problem.&lt;/LI&gt;&lt;LI&gt;Then I added the &lt;FONT face="courier new,courier"&gt;deploymentclient.conf&lt;/FONT&gt; and it pulled its apps (LDAP, Outputs) from the DS it stopped working.&lt;/LI&gt;&lt;LI&gt;This was useful and allowed us to identify that in fact it must be the LDAP app. &lt;FONT face="courier new,courier"&gt;outputs.conf&lt;/FONT&gt; is benign.&lt;/LI&gt;&lt;LI&gt;I had of course checked the logs previously but it was not clear. However there was a hint in the UI that the role could not despatch to indexers&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="courier new,courier"&gt;authorize.conf&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;[admin] role &amp;gt; &lt;FONT face="courier new,courier"&gt;dispatch_rest_to_indexers = disabled&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;changed to &lt;FONT face="courier new,courier"&gt;enabled&lt;/FONT&gt; and restarted Splunk Daemon&lt;/LI&gt;&lt;LI&gt;Resolved&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This had not been obvious as the LDAP app had been packaged previously but not consistently deployed between the test environment and the production environment. This &lt;A href="https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-gettin-the-warning-quot-Restricting-results-of-the-quot/m-p/420401" target="_blank" rel="noopener"&gt;other posting also proved useful.&lt;/A&gt; I don't think the Admin / Clustering / Core Implementation course points this importance out and generally not much is written on the MC. Perhaps we can improve the course material, and definitely good experience gained personally.&lt;/P&gt;&lt;P&gt;The client was satisfied with the reproduction of the issue also and closes out the problem.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 19:47:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Monitoring-Console-not-functional-after-pass4SymmKey-update-v9-0/m-p/627515#M15141</guid>
      <dc:creator>NullZero</dc:creator>
      <dc:date>2023-01-18T19:47:22Z</dc:date>
    </item>
  </channel>
</rss>

