Deployment Architecture

Why am I getting error "CONFIGURATION ID MISMATCH" trying to add another search head to my search head cluster?

wweiland
Contributor

I'm trying to add another search head to my search head cluster. I'm receiving the following error when I try and bootstrap it.

[labsplunk-sh:/opt/sh2a/bin]$ ./splunk bootstrap shcluster-captain -servers_list "https://#.#.#.#:8088,https://#.#.#.#:8090,https://#.#.#.#:8091,https://#.#.#.#:8092,https://#.#.#.#:8093"

 In handler 'shclustermemberconsensus': CONFIGURATION ID MISMATCH

server.conf
[shclustering]
disabled = 0
mgmt_uri = https://#.#.#.#:8093
pass4SymmKey = XXXXXXXX
adhoc_searchhead = true
conf_deploy_fetch_url = https://#.#.#.#:8088

It's a fresh Splunk tar, but the cluster is in use with deployed apps/configuration, so I don't want to delete everything and start over. The only thing I did to the SH was set the licenser, cluster-config, shcluster-config, and the deployer. This is the only line in the log to indicate the problem.

Anyone else seen this issue or any suggestions on how to fix? I've restarted the whole cluster with no change.

0 Karma
1 Solution

wweiland
Contributor

Finally got it working. I had to set a static captain, add the system, go back to dynamic captain.

View solution in original post

0 Karma

wweiland
Contributor

Finally got it working. I had to set a static captain, add the system, go back to dynamic captain.

0 Karma

somesoni2
Revered Legend

Make sure that the conf_deploy_fetch_url is correct and pass4SymmKey is matching with all other existing members.

0 Karma

somesoni2
Revered Legend
0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...