Installation

Getting distributed search key error when trying to upgrade to Splunk 6.1.1.

carlitosway
New Member

Has anyone experienced this error? I'm using a single deployment not a distributed one.

Since the file was missing, I generated a generic distsearch.conf file and placed it under /opt/splunk/etc/system/local and still get the same error when I try and start splunk.

Migrating to:
VERSION=6.1.1
BUILD=207789
PRODUCT=splunk
PLATFORM=Linux-i386

********** BEGIN PREVIEW OF CONFIGURATION FILE MIGRATION **********

Unable to generate distributed search keys.

An error occurred: no 'tokenExchKeys' stanza exists in distsearch.conf. Your configuration may be corrupt or may be corrupt or may require a restart.

Labels (2)
0 Karma

vkora
New Member

Following worked for me:

$ cp /opt/splunk/etc/system/default/distsearch.conf /opt/splunk/etc/system/local/distsearch.conf

$ chmod 640 /opt/splunk/etc/system/local/distsearch.conf
$ cd /opt/splunk/etc/auth/distServerKeys
$ mv private.pem private.pem_old
$ mv trusted.pem trusted.pem_old
$ splunk restart

0 Karma

carlitosway
New Member

I'm running this OS.
Linux hostname 3.2.0-4-686-pae #1 SMP Debian 3.2.57-3 i686 GNU/Linux

0 Karma

carlitosway
New Member

WoW quick update, backed up all the configurations, indexes and deleted everything. Installed it from scratch and still get this error.

This appears to be your first time running this version of Splunk.
.........
Generating RSA private key, 1024 bit long modulus
........++++++
..............................................++++++
e is 65537 (0x10001)
writing RSA key

Unable to generate distributed search keys.

An error occurred: no 'tokenExchKeys' stanza exists in distsearch.conf. Your configuration may be corrupt or may require a restart.

0 Karma

carlitosway
New Member

Still have this problem, it did not go away with 6.1.2.

Migrating to:
VERSION=6.1.2
BUILD=213098
PRODUCT=splunk
PLATFORM=Linux-i386

Unable to generate distributed search keys.

An error occurred: no 'tokenExchKeys' stanza exists in distsearch.conf. Your configuration may be corrupt or may require a restart.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...