Deployment Architecture

How can I determine where socket timeout is coming from when I peer indexer to search head?

sammarder
New Member

I am trying to solve an issue with some search heads that have had issues accepting a set of indexers. I am trying to add in indexers that have been networked to a new set of search heads. When I try to add them in, I get the response Socket error communicating with splunkd (error=timed out), path = /servicesNS/admin/search/search/distributed/peers. I have tried looking around for this error message but I cant find anything that is quite like the situation I am seeing.

What I have tried thus far:
- Update sendTimeout in distsearch.conf on the search head to 60 seconds and restart splunk. The change took but the indexers still appeared down to the new search head
- I have also noticed a splunkdtimeout in the web.conf setting file but I am not sure if that is a red herring.
- I am also interested if it could be the indexer itself despite the indexer working for other servers.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...