Getting Data In

Why am I seeing "Authentication failed" in the Distributed Management Console for search peers added using CLI commands in a script?

kimche
Path Finder

Hi all,

I add the search peers by using the CLI commands in a script. When I check the Distributed Management Console UI, I see that the status for all of them is "Authentication failed". The credentials provided are correct. If I delete them and re-add them manually (I just copy the exact servername:port) they are instantly "Up". What extra step am I missing in my script to have them up instantly?

Thanks,

Kimche

0 Karma
1 Solution

kimche
Path Finder

This problem has been solved once I edited the distsearch.conf with distributed search groups with other names ([distributedSearch:dmc_group_indexer] instead of [distributedSearch:indexer]). After that all the instances were Up again.

View solution in original post

kimche
Path Finder

This problem has been solved once I edited the distsearch.conf with distributed search groups with other names ([distributedSearch:dmc_group_indexer] instead of [distributedSearch:indexer]). After that all the instances were Up again.

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...