Monitoring Splunk

I just setup a search head deployer in docker and i am getting the below error on all three search heads.

enmanu
New Member

10-17-2018 03:54:47.137 +0000 WARN ConfReplication - downloadDeployableApps: Got zero-size baseline configuration
10-17-2018 03:54:47.137 +0000 WARN ConfReplication - downloadDeployableApps: Error listing baseline configuration: Non-200/201 status_code=401; {"messages":[{"type":"ERROR","text":"Unauthorized"}]}
10-17-2018 03:54:47.036 +0000 WARN ConfReplication - downloadDeployableApps: Waiting 100ms ...
10-17-2018 03:54:47.036 +0000 WARN ConfReplication - downloadDeployableApps: Error listing baseline configuration: Non-200/201 status_code=401; {"messages":[{"type":"ERROR","text":"Unauthorized"}]}
10-17-2018 03:54:46.935 +0000 WARN ConfReplication - downloadDeployableApps: Waiting 100ms ...
10-17-2018 03:54:46.935 +0000 WARN ConfReplication - downloadDeployableApps: Error listing baseline configuration: Non-200/201 status_code=401; {"messages":[{"type":"ERROR","text":"Unauthorized"}]}

Tags (1)
0 Karma

akandi
Loves-to-Learn

Following could be possible reason for this error:

1) secret key between deployer and cluster members are not same.
2) Make sure each member on search head cluster have different server name. In case server name is same with any member then it will give this error.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi enmanu,

Indeed it is a permission problem, but not one you're thinking of 😉

The problem is most likely caused by a mismatching pass4SymmKey and is described in the docs here http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/PropagateSHCconfigurationchanges#Set_a...

If you're 100% sure the keys match, read this answer which provides a lot of information about troubleshooting a SHC https://answers.splunk.com/answers/242905/shc-troubleshooting-configurations-under-search-he.html

Hope this helps ...

cheers, MuS

0 Karma

skalliger
SplunkTrust
SplunkTrust

Looks like a permission problem. Did you check permisisons on directories are set correctly?

0 Karma

enmanu
New Member

Thank you for your response. I have checked the permissions. The error wont go away

0 Karma

yamila123
Loves-to-Learn

did you ever get this resolved?  I am experiencing the same issue and wondering if you had figured out a solution

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...