Deployment Architecture

Why am I getting error "CONFIGURATION ID MISMATCH" trying to add another search head to my search head cluster?

wweiland
Contributor

I'm trying to add another search head to my search head cluster. I'm receiving the following error when I try and bootstrap it.

[labsplunk-sh:/opt/sh2a/bin]$ ./splunk bootstrap shcluster-captain -servers_list "https://#.#.#.#:8088,https://#.#.#.#:8090,https://#.#.#.#:8091,https://#.#.#.#:8092,https://#.#.#.#:8093"

 In handler 'shclustermemberconsensus': CONFIGURATION ID MISMATCH

server.conf
[shclustering]
disabled = 0
mgmt_uri = https://#.#.#.#:8093
pass4SymmKey = XXXXXXXX
adhoc_searchhead = true
conf_deploy_fetch_url = https://#.#.#.#:8088

It's a fresh Splunk tar, but the cluster is in use with deployed apps/configuration, so I don't want to delete everything and start over. The only thing I did to the SH was set the licenser, cluster-config, shcluster-config, and the deployer. This is the only line in the log to indicate the problem.

Anyone else seen this issue or any suggestions on how to fix? I've restarted the whole cluster with no change.

0 Karma
1 Solution

wweiland
Contributor

Finally got it working. I had to set a static captain, add the system, go back to dynamic captain.

View solution in original post

0 Karma

wweiland
Contributor

Finally got it working. I had to set a static captain, add the system, go back to dynamic captain.

0 Karma

somesoni2
Revered Legend

Make sure that the conf_deploy_fetch_url is correct and pass4SymmKey is matching with all other existing members.

0 Karma

somesoni2
Revered Legend
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...