<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClusterManager Peer connection failed in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749788#M12590</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309363"&gt;@Mirza_Jaffar1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you copy the $SPLUNK_HOME/etc/auth/splunk.secret file from the old to the new server? This is the file that Splunk uses for encrypting sensitive configuration/secrets and is unique to each server, unless copied.&lt;/P&gt;&lt;P&gt;Regarding the permissions issues, did you manage to resolve these? Who are the the files/folders owned by and what user is the Splunk service running as?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jul 2025 21:38:57 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-07-14T21:38:57Z</dc:date>
    <item>
      <title>ClusterManager Peer connection failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/748317#M12552</link>
      <description>&lt;P&gt;what does indicates&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;06-19-2025 11:09:33.046 +0000 ERROR AesGcm [65605 MainThread] - Text decryption - error in finalizing: No errors in queue&lt;BR /&gt;06-19-2025 11:09:33.046 +0000 ERROR AesGcm [65605 MainThread] - AES-GCM Decryption failed!&lt;BR /&gt;06-19-2025 11:09:33.047 +0000 ERROR Crypto [65605 MainThread] - Decryption operation failed: AES-GCM Decryption failed!&lt;BR /&gt;06-19-2025 11:09:33.081 +0000 ERROR AesGcm [65605 MainThread] - Text decryption - error in finalizing: No errors in queue&lt;BR /&gt;06-19-2025 11:09:33.081 +0000 ERROR AesGcm [65605 MainThread] - AES-GCM Decryption failed!&lt;BR /&gt;06-19-2025 11:09:33.081 +0000 ERROR Crypto [65605 MainThread] - Decryption operation failed: AES-GCM Decryption failed!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 11:32:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/748317#M12552</guid>
      <dc:creator>Mirza_Jaffar1</dc:creator>
      <dc:date>2025-06-19T11:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterManager Peer connection failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/748326#M12553</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309363"&gt;@Mirza_Jaffar1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no mention of SSL in the error logs so I am leaning towards an issue with the pass4SymmKey or another encrypted credential. Have you recently made any changes or installed any apps?&lt;/P&gt;&lt;P&gt;If you copied a local directory from another instance that contained encrypted credentials then this instance will be unable to decrypt them, this is because Splunk encrypts credentials based on its own splunk.secret file&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can verify encrypted keys such as pass4SymmKey by using:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$SPLUNK_HOME/bin/splunk show-decrypted --value '&amp;lt;value&amp;gt;'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When using this you need to change the $ -&amp;gt; \$ otherwise Linux will think this is a variable. for example $7$abc -&amp;gt; \$7\$abc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please let us know what your architecture is like, e.g. what instance is this within your architecture and if you made any recent changes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 12:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/748326#M12553</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-19T12:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterManager Peer connection failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749777#M12586</link>
      <description>&lt;OL&gt;&lt;LI&gt;yes the local directory was copied from another instance&lt;/LI&gt;&lt;LI&gt;Tried to sync the directory from instance idx old to instance idx new&lt;/LI&gt;&lt;LI&gt;There seem some permission issues during the migration&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 14 Jul 2025 21:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749777#M12586</guid>
      <dc:creator>Mirza_Jaffar1</dc:creator>
      <dc:date>2025-07-14T21:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterManager Peer connection failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749782#M12587</link>
      <description>&lt;P&gt;Actually, you need to escape the&amp;nbsp;dollar sign if you are&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt; using single quotes in most shells. If you are using single quotes for strings you should not escape the contents.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;:/ $ echo \$
$
:/ $ echo "\$"
$
:/ $ echo '$'
$
:/ $ echo '\$'
\$&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 14 Jul 2025 21:30:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749782#M12587</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-14T21:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterManager Peer connection failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749784#M12588</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309363"&gt;@Mirza_Jaffar1&lt;/a&gt;&amp;nbsp;Ok, so you tried to copy over the contents of old server's config to a new one, right? There were "some permission issues", right? Did you bother to check what kind of issues they were? Did you fix them?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 21:33:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749784#M12588</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-14T21:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterManager Peer connection failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749786#M12589</link>
      <description>&lt;P&gt;I did check but nothing seems worked because chmod 770 is what used but chmod 550 should work! This something when usually occurs with permission.&lt;/P&gt;&lt;P&gt;Is there any other chmod numeric(550.775,7770) which provide same permission to the root and user?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 21:37:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749786#M12589</guid>
      <dc:creator>Mirza_Jaffar1</dc:creator>
      <dc:date>2025-07-14T21:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterManager Peer connection failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749788#M12590</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309363"&gt;@Mirza_Jaffar1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you copy the $SPLUNK_HOME/etc/auth/splunk.secret file from the old to the new server? This is the file that Splunk uses for encrypting sensitive configuration/secrets and is unique to each server, unless copied.&lt;/P&gt;&lt;P&gt;Regarding the permissions issues, did you manage to resolve these? Who are the the files/folders owned by and what user is the Splunk service running as?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 21:38:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749788#M12590</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-14T21:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterManager Peer connection failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749789#M12591</link>
      <description>&lt;P&gt;Nice thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; - I rarely use single quotes with $ in so had assumed incorrectly it was the same as double quotes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every day is a school day &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 21:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/749789#M12591</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-14T21:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterManager Peer connection failed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/756291#M12784</link>
      <description>&lt;P&gt;can you please validate the below what could be issues as pe the config&lt;/P&gt;&lt;P&gt;splunk@mc1:/opt/splunk/etc/apps/ci1_unhash_app/local$ /opt/splunk/bin/splunk _internal call /storage/passwords/test&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;QUERYING: '&lt;A href="https://127.0.0.1:8089/services/storage/passwords/test" target="_blank" rel="nofollow noopener noreferrer"&gt;https://127.0.0.1:8089/services/storage/passwords/test&lt;/A&gt;'&lt;BR /&gt;WARNING: Server Certificate Hostname Validation is disabled. Please see server.conf/[sslConfig]/cliVerifyServerName for details.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Your session is invalid. Please login.&lt;BR /&gt;Splunk username: admin&lt;BR /&gt;Password:&lt;BR /&gt;FAILED: 'HTTP/1.1 404 Not Found'&lt;BR /&gt;Content:&lt;BR /&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;response&amp;gt;&lt;BR /&gt;&amp;lt;messages&amp;gt;&lt;BR /&gt;&amp;lt;msg type="ERROR"&amp;gt;Could not find object id=:test:&amp;lt;/msg&amp;gt;&lt;BR /&gt;&amp;lt;/messages&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;/P&gt;&lt;P&gt;splunk@mc1:/opt/splunk/etc/apps/ci1_unhash_app/local$ ll&lt;BR /&gt;total 16&lt;BR /&gt;drwxrwxr-x 2 splunk splunk 4096 Dec 8 18:53 ./&lt;BR /&gt;drwxrwxr-x 4 splunk splunk 4096 Dec 8 18:36 ../&lt;BR /&gt;-rw-rw-r-- 1 splunk splunk 110 Dec 8 18:19 app.conf&lt;BR /&gt;-rw-rw-r-- 1 splunk splunk 91 Dec 8 18:53 passwords.conf&lt;BR /&gt;splunk@ci1-persn000000001356580-mc1:/opt/splunk/etc/apps/ci1_unhash_app/local$ cat passwords.conf&lt;BR /&gt;[credential::test:]&lt;BR /&gt;password = $7$N/ZmtDftfjp7/ij6VGZeXh1l3UU2T6Ve+Hem3JCNna6upxmTvMDjSi==&lt;BR /&gt;splunk@mc1:/opt/splunk/etc/apps/ci1_unhash_app/local$&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 19:18:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/ClusterManager-Peer-connection-failed/m-p/756291#M12784</guid>
      <dc:creator>Mirza_Jaffar1</dc:creator>
      <dc:date>2025-12-08T19:18:02Z</dc:date>
    </item>
  </channel>
</rss>

