Monitoring Splunk

Why is difficult getting cluster to work?

domino30
Path Finder

Yes indexer clustering. I set up 3 win 10 machines with Splunk Enterprise on them and got them to initially connect to master indexer but then got this error.

on same dns and firewall turned off on all 3 machines.

 

thanks

 

 

Labels (1)
0 Karma
1 Solution

shivanshu1593
Builder

The error message in your screenshot indicates that the machine with the same name is already registered. Did you copy/paste Splunk directory from one to the VMs in question? Please check their GUIDs and see if they are matching. If they are, wipe out Splunk on one of them, reinstall and have it join the cluster again. 

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

View solution in original post

shivanshu1593
Builder

The error message in your screenshot indicates that the machine with the same name is already registered. Did you copy/paste Splunk directory from one to the VMs in question? Please check their GUIDs and see if they are matching. If they are, wipe out Splunk on one of them, reinstall and have it join the cluster again. 

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

isoutamo
SplunkTrust
SplunkTrust

Hi

if you are using a “golden image” then you should follow these steps, not just copy paste. https://docs.splunk.com/Documentation/Splunk/9.0.3/Admin/IntegratefullSplunkontoasystemimage
Otherwise you will get situation which @shivanshu1593 already describe.

r. Ismo

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...