Getting Data In

Search head is not communicating with its peer(Indexer)

ashishlal82
Explorer

Error [00000080] Instance name "XXX.XXX.XXX.XXX:8089" REST interface to peer is taking longer than 5 seconds to respond on https. Peer may be over subscribed or misconfigured. Check var/log/splunk/splunkd_access.log on the peer Last Connect Time:2018-01-12T09:46:13.000-05:00; Failed 10 out of 10 times.

0 Karma

nickhills
Ultra Champion

Assuming no Splunk config changes, could your indexer be bogged down with something else?
From the searchhead try:
curl -k -u admin:changeme https://your_missing_indexer:8089/services/server/info

If you get no response, check the normal things, such as "is splunk actually running", server load, network etc etc

Aldo take a look for errors in /opt/splunk/var/log/splunk/splunkd.log?

If my comment helps, please give it a thumbs up!

mayurr98
Super Champion
0 Karma

ashishlal82
Explorer

I don't think that is the issue. I have 2 indexers. One of the indexer is working fine and is connected to search head but the other is not.

0 Karma

Amulya888
Explorer

I have the similar issue.
Please give us the solution for this.

0 Karma

dmjenso
Engager

I had this issue and I had to distribute the public SSL key from the search head to the peer (indexer).

Settings > Distributed Search > Search Peers >

click on the peer in question and enter the admin/password

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...