Monitoring Splunk

I just setup a search head deployer in docker and i am getting the below error on all three search heads.

enmanu
New Member

10-17-2018 03:54:47.137 +0000 WARN ConfReplication - downloadDeployableApps: Got zero-size baseline configuration
10-17-2018 03:54:47.137 +0000 WARN ConfReplication - downloadDeployableApps: Error listing baseline configuration: Non-200/201 status_code=401; {"messages":[{"type":"ERROR","text":"Unauthorized"}]}
10-17-2018 03:54:47.036 +0000 WARN ConfReplication - downloadDeployableApps: Waiting 100ms ...
10-17-2018 03:54:47.036 +0000 WARN ConfReplication - downloadDeployableApps: Error listing baseline configuration: Non-200/201 status_code=401; {"messages":[{"type":"ERROR","text":"Unauthorized"}]}
10-17-2018 03:54:46.935 +0000 WARN ConfReplication - downloadDeployableApps: Waiting 100ms ...
10-17-2018 03:54:46.935 +0000 WARN ConfReplication - downloadDeployableApps: Error listing baseline configuration: Non-200/201 status_code=401; {"messages":[{"type":"ERROR","text":"Unauthorized"}]}

Tags (1)
0 Karma

akandi
Loves-to-Learn

Following could be possible reason for this error:

1) secret key between deployer and cluster members are not same.
2) Make sure each member on search head cluster have different server name. In case server name is same with any member then it will give this error.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi enmanu,

Indeed it is a permission problem, but not one you're thinking of 😉

The problem is most likely caused by a mismatching pass4SymmKey and is described in the docs here http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/PropagateSHCconfigurationchanges#Set_a...

If you're 100% sure the keys match, read this answer which provides a lot of information about troubleshooting a SHC https://answers.splunk.com/answers/242905/shc-troubleshooting-configurations-under-search-he.html

Hope this helps ...

cheers, MuS

0 Karma

skalliger
SplunkTrust
SplunkTrust

Looks like a permission problem. Did you check permisisons on directories are set correctly?

0 Karma

enmanu
New Member

Thank you for your response. I have checked the permissions. The error wont go away

0 Karma

yamila123
Loves-to-Learn

did you ever get this resolved?  I am experiencing the same issue and wondering if you had figured out a solution

0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...