Deployment Architecture

Error: Unable to distribute to peer because peer has status ="Authentication failed

keerthana_k
Communicator

I am getting error "Unable to distribute to peer named lonrs10457 at uri https://SPLUNK-IDX1:8089 because peer has status ="Authentication failed"" in our Search Head while executing any search. I have a distributed search setup. I have checked the status under Manager » Distributed search » Search peers>. Only the Indexer is shown as up and running with Status=Up and Replication status=Succesful.

Tags (1)
0 Karma

Simeon
Splunk Employee
Splunk Employee

That error typically means that you cannot search the remote peer. This can be due to privileges against the remote peer or a problem with how you have added it as a peer. The authentication to a remote peer is tokenized, so if it previously worked then it is likely that there may be a connectivity problem or change in that token.

0 Karma

MHibbin
Influencer

you also have to make sure you are not using the default admin password (i.e. changeme), as this will not work... but then I'd assume you are not if you have already added it... but then again, assume nothing 🙂

0 Karma

kristian_kolb
Ultra Champion

have you tried to remove the search peer and adding it back again? Note that you need the proper credentials for the splunkd (i.e. indexer) you want to add back as a search peer.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...