I reinstalled a splunk indexer on a machine (10.1.2.3) that had crashed with total data failure. Copied over the conf files from a similar machine a 10.1.2.3 and now one of the search heads is giving this msg in the log file:
WARN UserManagerPro - Unable to get authentication token from peeruri="h t t p s : / / 10.1.2.3:8089".
How can I fix this?
edit: I had to insert blank spaces in the https part because I got a not enough karma to post external urls when i did it normally.
Hopefully this resolved by now. This usually appears when the search head cannot authenticate with search peers in the distributed environment. Pls re-authenticate either using CLI or from the GUI within the search head : settings-> distributed search -> Search peers and ensure, its up and enabled.