Why won't search head join the cluster?


Hi, Greetings

I'm trying to add a search heads to an existing cluster by updating the server.conf file.

To be more specific I'm adding three search head.

One search head added successfully, but when I repeat the same steps in other two search heads. It doesn't joins the cluster.

I see the below is the sout when Splunk is restarted.

Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking appserver port []: open
Checking kvstore port [8191]: open
Checking configuration... Done.
Checking critical directories... Done
Checking indexes...
Validated: _audit _internal _introspection _telemetry _thefishbucket history main summary

Bypassing local license checks since this instance is configured with a remote license master.

Checking filesystem compatibility... Done
Checking conf files for problems...
Checking default conf files for edits...
Validating installed files against hashes from '/opt/splunk/splunk-7.1.1-8f0ead9ec3db-linux-2.6-x86_64-manifest'
All installed files intact.
Checking replication_port port [8090]: open
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
[ OK ]

Waiting for web server at to be available...........

WARNING: web interface does not seem to be available!

Please advise.



Labels (2)
0 Karma


@charival based on your output I can see that you're running Splunk Enterprise on that instance with a outdated version (7.1.1) that  is no longer supported as of October 31, 2020.

Please verify if all other searchheads in your cluster are running on the same version. Maybe you have some compatibility issues. 

If the other peers are running on a higher version upgrade the affected instance and then try to add it again.

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...