Installation

pass4SymmKey didn't help with "Bad Request — In handler 'localslave': editTracker failed, reason='WARN: path=/masterlm/usage: invalid signature on request from ip=XX.XX.XX.XX"

yaraslau_haradz
New Member

I have Sarchhead and 4 indexers connected to it. (Indexer_lic, Indexer1, Indexer2, Indexer3).
Indexer_lic operates as License Master.
I migrated Indexer_lic from one machine to another.
Searchhead, Indexer1 and Indexer2 were connected to License Maser as Slaves successfully

When I'm trying to connect slave Indexer3(IP 172.18.32.156) to License master I get next error:
"Bad Request — In handler 'localslave': editTracker failed, reason='WARN: path=/masterlm/usage: invalid signature on request from ip=172.18.32.156'"

I replaced next string in file splunk/etc/system/local/server.conf with next value and restarted Licnese Master:
"[general]
pass4SymmKey = changeme"

Then I did the same for Indexer3.

After restarting error while setting License Master URI still present:
"Bad Request — In handler 'localslave': editTracker failed, reason='WARN: path=/masterlm/usage: invalid signature on request from ip=172.18.32.156'"

Indexer3 is located in another network and I use NAT (network address translation) to connect to License master.
I checked connection to License master using Linux command line at Indexer3. Port is opened, connection is available.
"telnet 194.39.131.7 8089
Trying 194.39.131.7...
Connected to 194.39.131.7.
Escape character is '^]'.
^]
telnet> sfd
?Invalid command
telnet> ^C"

Could you please help me to connect my Indexer3 server to License Master.
Issue is urgent because I'll get License violation and search will stop to work for all cluster.

Labels (2)
0 Karma
1 Solution

masonmorales
Influencer

Check your case and syntax again on Indexer3 and restart it. What you posted looks fine and the error is pretty explicit. Updating the pass4SymmKey to match the license master's and then restarting Splunk has always worked for me in resolving this error. If you can't get it, open a Splunk Support case.

View solution in original post

0 Karma

masonmorales
Influencer

Check your case and syntax again on Indexer3 and restart it. What you posted looks fine and the error is pretty explicit. Updating the pass4SymmKey to match the license master's and then restarting Splunk has always worked for me in resolving this error. If you can't get it, open a Splunk Support case.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...