Getting Data In

After deploying a search head clustering, why is authentication to my two indexers failing and am unable to search?

slawny86
New Member

After deploying a search head cluster, I have a problem with searching anything. SHcluster status is up, but when I logged on each shcluster members, I've noticed in "Distributed environment" -> "Distributed search" -> "Search peers" that authentication to my two indexers failed. In server.conf on each member, pass4SymmKey in [general] stanza and [shclustering] stanza is the same. Has anyone had a similar problem?

0 Karma

slawny86
New Member

Hello,

I had found solution these problem, pass4SymmKey should be the same for shcluter and indexer cluster

0 Karma

slawny86
New Member

and I had to change shcluster's member server name in inputs.conf and server.conf, because were duplicated for some hosts in the cluster. After that the problem disaperaed

0 Karma

jplumsdaine22
Influencer

What error did you get after running the splunk edit cluster-config command on the search heads as descibed here: http://docs.splunk.com/Documentation/Splunk/6.3.3/DistSearch/SHCandindexercluster

0 Karma

slawny86
New Member

Yes, indexers are also in a cluster

0 Karma

sk314
Builder

Are your indexers also in a cluster?

0 Karma

sk314
Builder
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...