Deployment Architecture

Why are we getting "Error, Parameters must be in the form '-parameter value'" during search head cluster member initialization?

att35
Builder

Hi,

I am trying to setup a Search Head Cluster, and during the Cluster member initialization step, ./splunk init shcluster-config command always results in

Error, Parameters must be in the form '-parameter value'

Double checked all values and there are no typos. Only item I am not using is "shcluster_label" which the guide says is optional.

Following steps from: http://docs.splunk.com/Documentation/Splunk/6.4.0/DistSearch/SHCdeploymentoverview

Please assist.

Thanks,

~ Abhi

0 Karma
1 Solution

att35
Builder

Hi,

Initially I had copied from the manual and edited the values but later manually typed the command and was getting the same error.

I was able to finally get it working by removing the "-secret" parameter from the command. After that it worked and displayed
Search head clustering has been initialized on this node.
You need to restart the Splunk Server (splunkd) for your changes to take effect.

I had set the pass4SymmKey already under server.conf. Could this be the reason for the the error? Maybe it was rejecting the parameter as it's already present in the file?

After that, I was able to successfully bootstrap and set the captain. "splunk show shcluster-status" confirms that all members are up.

Thanks,

~ Abhi

View solution in original post

0 Karma

att35
Builder

Hi,

Initially I had copied from the manual and edited the values but later manually typed the command and was getting the same error.

I was able to finally get it working by removing the "-secret" parameter from the command. After that it worked and displayed
Search head clustering has been initialized on this node.
You need to restart the Splunk Server (splunkd) for your changes to take effect.

I had set the pass4SymmKey already under server.conf. Could this be the reason for the the error? Maybe it was rejecting the parameter as it's already present in the file?

After that, I was able to successfully bootstrap and set the captain. "splunk show shcluster-status" confirms that all members are up.

Thanks,

~ Abhi

0 Karma

jkat54
SplunkTrust
SplunkTrust

I converted this to the answer. Please mark it as such.

did you have a space between -secret and it's value? IF you're really curious, please open another question.

0 Karma

somesoni2
Revered Legend

Are you copying the command from somewhere (notepad/word) OR typing the whole command?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...