Deployment Architecture

What is the value of pass4symmkey on searchhead members

rashi83
Path Finder

Hi , I want to understand when SHC is enabled , does the cluster members ( /opt/apps/splunk/etc/system/local/server.conf)

[shclustering]
conf_deploy_fetch_url = https://xxxxx:8089
disabled = 0
mgmt_uri = https://xxxxxx:8089
pass4SymmKey = $7$iExLu2lY4pfhmcXKg0bzvFrlGBiiz8ZsgeNOw8V/eggWX/UHplXMSX4=

Does this pass4Symmkey encrypted same on cluster members ? I am seeing different pass4Symmkey on other member . Is that a problem ?

[shclustering]
conf_deploy_fetch_url = https://xxxx:8089
disabled = 0
mgmt_uri = https://xxxxx:8089
pass4SymmKey = $7$ILXF6T0d2rhloLGdszMDKaL/H002O09I4zidU0PzN9aglnG5+wSnoWM=
shcluster_label = shcluster1
id = 2FCF8358-15EC-4F17-A119-63A6CEE4734C

Labels (2)
0 Karma
1 Solution

codebuilder
Influencer

The hashing algorithm is different between versions, but the short answer is yes, the hashed value can be different between cluster members. Always use the plain text version when adding new members, don't copy the hashed value from another member. As long as your SHC shows healthy you are good.

----
An upvote would be appreciated and Accept Solution if it helps!

View solution in original post

0 Karma

codebuilder
Influencer

The hashing algorithm is different between versions, but the short answer is yes, the hashed value can be different between cluster members. Always use the plain text version when adding new members, don't copy the hashed value from another member. As long as your SHC shows healthy you are good.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...