Deployment Architecture

Why am I getting error "CONFIGURATION ID MISMATCH" trying to add another search head to my search head cluster?

wweiland
Contributor

I'm trying to add another search head to my search head cluster. I'm receiving the following error when I try and bootstrap it.

[labsplunk-sh:/opt/sh2a/bin]$ ./splunk bootstrap shcluster-captain -servers_list "https://#.#.#.#:8088,https://#.#.#.#:8090,https://#.#.#.#:8091,https://#.#.#.#:8092,https://#.#.#.#:8093"

 In handler 'shclustermemberconsensus': CONFIGURATION ID MISMATCH

server.conf
[shclustering]
disabled = 0
mgmt_uri = https://#.#.#.#:8093
pass4SymmKey = XXXXXXXX
adhoc_searchhead = true
conf_deploy_fetch_url = https://#.#.#.#:8088

It's a fresh Splunk tar, but the cluster is in use with deployed apps/configuration, so I don't want to delete everything and start over. The only thing I did to the SH was set the licenser, cluster-config, shcluster-config, and the deployer. This is the only line in the log to indicate the problem.

Anyone else seen this issue or any suggestions on how to fix? I've restarted the whole cluster with no change.

0 Karma
1 Solution

wweiland
Contributor

Finally got it working. I had to set a static captain, add the system, go back to dynamic captain.

View solution in original post

0 Karma

wweiland
Contributor

Finally got it working. I had to set a static captain, add the system, go back to dynamic captain.

0 Karma

somesoni2
Revered Legend

Make sure that the conf_deploy_fetch_url is correct and pass4SymmKey is matching with all other existing members.

0 Karma

somesoni2
Revered Legend
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...