Installation

Why won't search head join the cluster?

charival
Observer

Hi, Greetings

I'm trying to add a search heads to an existing cluster by updating the server.conf file.

To be more specific I'm adding three search head.

One search head added successfully, but when I repeat the same steps in other two search heads. It doesn't joins the cluster.

I see the below is the sout when Splunk is restarted.

Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking appserver port [127.0.0.1:8065]: open
Checking kvstore port [8191]: open
Checking configuration... Done.
Checking critical directories... Done
Checking indexes...
Validated: _audit _internal _introspection _telemetry _thefishbucket history main summary
Done


Bypassing local license checks since this instance is configured with a remote license master.

Checking filesystem compatibility... Done
Checking conf files for problems...
Done
Checking default conf files for edits...
Validating installed files against hashes from '/opt/splunk/splunk-7.1.1-8f0ead9ec3db-linux-2.6-x86_64-manifest'
All installed files intact.
Done
Checking replication_port port [8090]: open
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Done
[ OK ]

Waiting for web server at http://127.0.0.1:8000 to be available...........

WARNING: web interface does not seem to be available!

Please advise.

Thanks,

CG

Labels (2)
0 Karma

PaulPanther
Motivator

@charival based on your output I can see that you're running Splunk Enterprise on that instance with a outdated version (7.1.1) that  is no longer supported as of October 31, 2020.

Please verify if all other searchheads in your cluster are running on the same version. Maybe you have some compatibility issues. 

If the other peers are running on a higher version upgrade the affected instance and then try to add it again.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...