Getting Data In

How to troubleshoot why 1 indexer in a Splunk indexer cluster crashed and won't restart with a "Bad Decrypt" error?

basher590
Engager

HI,

I have inherited a clustered Splunk setup and I noticed that 1 of my 2 indexers had crashed a couple of days ago.
Trying to restart it yields a Splunk timed out waiting to start error. Looking at the splunkd log I see the following error:

02-22-2016 14:05:35.800 +0000 ERROR SSLCommon - Can't read key file C:\Program Files\Splunk\etc\auth\server.pem errno=101077092 error:06065064:digital envelope routines:EVP_DecryptFinal_ex:bad decrypt.

The key file is there and looks OK to me, though I am not sure how I can test it. I did use the OpenSSL command, but received the same message. I tried changing the password in the config file and I receive a "bad password" error, so I know the PW is correct and it is reading the correct file.

There have been no updates or config changes that I am aware of, this 1 indexer server just seemed to crash.

Is it just a case of creating a new certificate on this one indexer, or are there other steps that need to be followed so I don't break the cluster / indexes?

I am running
Splunk Version
6.2.3
Splunk Build
264376

On Windows 2012 R2 servers.

Thanks

0 Karma
1 Solution

basher590
Engager

I got this fixed in the end by creating a new certificate and applying it to the faulty server.
The first restart worked but I received a new error relating to http://127.0.0.1 instead of https, but after another restart it cleared and all was good.

View solution in original post

0 Karma

basher590
Engager

I got this fixed in the end by creating a new certificate and applying it to the faulty server.
The first restart worked but I received a new error relating to http://127.0.0.1 instead of https, but after another restart it cleared and all was good.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...