Deployment Architecture

Why is hub2 unable to contact MCN?

Leon_P
Explorer

Hello all,

 

My setup has 2 hubs, Hub1 with 2 indexers and a Master Cluster node and hub2 with another 2 indexers and a standby Master Cluster node.

Hub1 is working as expected however hub2 is unable to contact the MCN.

None of the 3 servers in hub2 are able to do the health check of the MCN and when I do

“curl –k –vvv https://IP:8089/services/server/health/splunkd/local

It just times out.

I can curl to the local MCN in each hub and get the expected Unauthorized reply but not between hubs.

When I do TCPdump I can see the traffic hitting the MCN but never completing. Below is the output of the connection,

 

* Trying IP

* Connected to IP (IP) port 8089 (#0

* ALPN, offering h2

* ALPN, offering http/1.1

* Successfully set certificate verify locations:

*  CAfile: /etc/pki/tls/certs/ca-bundle.crt

CApath : none

* TLSv1.3 (OUT), tls handshake, Client hello (1):

* OpenSSL  SSL_Connect : SSL_ERROR_SYSCALL in connection to  IP:8089

* Closing Cconnection 0

 

any help would be much appreciated

 

Regards 

Leon

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

This doesn't appear to be a Splunk question, more a question for your network/infrastructure team.

For example, are the routing tables and switches set up correctly?

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This doesn't appear to be a Splunk question, more a question for your network/infrastructure team.

For example, are the routing tables and switches set up correctly?

0 Karma

Leon_P
Explorer

Hi,

 

Thanks, it was an MTU issue 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...