I reinstalled Splunk with clustering today. The problem is that I keep getting 'Signature mismatch between license slave' errors. I have the same Splunk Secret on all servers. Therefore I added the key already encrypted with the Splunk Secret in the server.conf for the installation.
I have already tried the following things:
Is this a bug or am I missing something fundamental?
Thanks for your help.
Rafael
Hi
I solved the problem with a work colleague. The problem wasn't that the signature didn't match. The error was that I accidentally entered a remote URI for the license master on the license master. However, the remote URI pointed to the server itself. But that doesn't work. The error message is simply misleading.
Greetings Rafael
Hi
I solved the problem with a work colleague. The problem wasn't that the signature didn't match. The error was that I accidentally entered a remote URI for the license master on the license master. However, the remote URI pointed to the server itself. But that doesn't work. The error message is simply misleading.
Greetings Rafael
The pass4SymmKey in the [general] stanza must match across your entire cluster.
For indexer clustering, the pass4SymmKey must also be set in the [clustering] stanza on the master and all indexers, and obviously match.
Master:
[clustering]
mode = master
pass4SymmKey = index_cluster_pw
...
Indexers:
[clustering]
mode = slave
pass4SymmKey = index_cluster_pw
...
It matches across thze entire cluster.
Are you running the license master on a dedicated node or one that also performs another Splunk role?
I solved the problem. Look the post below. Thank for your help.
Glad to help!
Also, be sure to add the pass4SymmKey in plain text and cycle Splunk. Don't copy over the encrypted value from another host.
This 100% helped me when I was having trouble licensing a slave node to the master and receiving the same error. Copying the unencrypted key into server.conf and then restarting Splunk made all the difference.