Monitoring Splunk

Search Peer unreachable

gitau_gm
Explorer

How do I resolve authentication or pass4SymmKey mismatch between search head and peer?
Also getting a situation where 0 clients phone home.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

That's two different things.

To resolve a pass4SymmKey mismatch, update the plain-text pass4SymmKey value in server.conf and restart the Splunk instance.  Splunk will encrypt the value when it restarts.  Repeat for each SH and peer.  Do NOT copy an encrypted pass4SymmKey from another Splunk instance.

Peers do not phone home so you must be referring to forwarders contacting the Deployment Server (DS).  Ensure all clients have the correct DS info in deploymentclient.conf and that the network permits connections from each client to the DS.

With more information about the problem(s) we can be more specific about the solution(s).

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

That's two different things.

To resolve a pass4SymmKey mismatch, update the plain-text pass4SymmKey value in server.conf and restart the Splunk instance.  Splunk will encrypt the value when it restarts.  Repeat for each SH and peer.  Do NOT copy an encrypted pass4SymmKey from another Splunk instance.

Peers do not phone home so you must be referring to forwarders contacting the Deployment Server (DS).  Ensure all clients have the correct DS info in deploymentclient.conf and that the network permits connections from each client to the DS.

With more information about the problem(s) we can be more specific about the solution(s).

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...