Deployment Architecture

Deployment Server throwing name resolution errors?

daniel333
Builder

all,

Out of no where my deployment server won't send data to my indexers nor will it read it's search peers. Everything points to network, but no other Splunk instances are impacted and they are all configured identically and in the same subnet. Very strange.

Error logs indicate that SPlunk cannot resolve the hosts. But I have no problem with name resolution elsewhere.

Encountered the following error while trying to save: Error while sending public key to search peer: Cannot resolve hostname
Tags (1)
0 Karma

somesoni2
Revered Legend

Try to remove and re-add the indexers search peers on that deployment server, or re-authenticate the search peer.

0 Karma

daniel333
Builder

Thanks, yes, did that and still name resolution errors.

I actually went in did a readd using IP and it was fine. Everything working as expected. Kinda strange. THe OS is having no troubles with name resolution, just splunkd.

Is there an internal setting for DNS on splunk I might not be aware of?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...