Getting Data In

Search head is not communicating with its peer(Indexer)

ashishlal82
Explorer

Error [00000080] Instance name "XXX.XXX.XXX.XXX:8089" REST interface to peer is taking longer than 5 seconds to respond on https. Peer may be over subscribed or misconfigured. Check var/log/splunk/splunkd_access.log on the peer Last Connect Time:2018-01-12T09:46:13.000-05:00; Failed 10 out of 10 times.

0 Karma

nickhills
Ultra Champion

Assuming no Splunk config changes, could your indexer be bogged down with something else?
From the searchhead try:
curl -k -u admin:changeme https://your_missing_indexer:8089/services/server/info

If you get no response, check the normal things, such as "is splunk actually running", server load, network etc etc

Aldo take a look for errors in /opt/splunk/var/log/splunk/splunkd.log?

If my comment helps, please give it a thumbs up!

mayurr98
Super Champion
0 Karma

ashishlal82
Explorer

I don't think that is the issue. I have 2 indexers. One of the indexer is working fine and is connected to search head but the other is not.

0 Karma

Amulya888
Explorer

I have the similar issue.
Please give us the solution for this.

0 Karma

dmjenso
Engager

I had this issue and I had to distribute the public SSL key from the search head to the peer (indexer).

Settings > Distributed Search > Search Peers >

click on the peer in question and enter the admin/password

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...