Splunk Enterprise Security

ClusterManager Peer connection failed

Mirza_Jaffar1
Loves-to-Learn

what does indicates

 

06-19-2025 11:09:33.046 +0000 ERROR AesGcm [65605 MainThread] - Text decryption - error in finalizing: No errors in queue
06-19-2025 11:09:33.046 +0000 ERROR AesGcm [65605 MainThread] - AES-GCM Decryption failed!
06-19-2025 11:09:33.047 +0000 ERROR Crypto [65605 MainThread] - Decryption operation failed: AES-GCM Decryption failed!
06-19-2025 11:09:33.081 +0000 ERROR AesGcm [65605 MainThread] - Text decryption - error in finalizing: No errors in queue
06-19-2025 11:09:33.081 +0000 ERROR AesGcm [65605 MainThread] - AES-GCM Decryption failed!
06-19-2025 11:09:33.081 +0000 ERROR Crypto [65605 MainThread] - Decryption operation failed: AES-GCM Decryption failed!

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Mirza_Jaffar1 

There is no mention of SSL in the error logs so I am leaning towards an issue with the pass4SymmKey or another encrypted credential. Have you recently made any changes or installed any apps?

If you copied a local directory from another instance that contained encrypted credentials then this instance will be unable to decrypt them, this is because Splunk encrypts credentials based on its own splunk.secret file 

You can verify encrypted keys such as pass4SymmKey by using:

$SPLUNK_HOME/bin/splunk show-decrypted --value '<value>'

 

When using this you need to change the $ -> \$ otherwise Linux will think this is a variable. for example $7$abc -> \$7\$abc

Please let us know what your architecture is like, e.g. what instance is this within your architecture and if you made any recent changes.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Actually, you need to escape the dollar sign if you are not using single quotes in most shells. If you are using single quotes for strings you should not escape the contents.

:/ $ echo \$
$
:/ $ echo "\$"
$
:/ $ echo '$'
$
:/ $ echo '\$'
\$

livehybrid
SplunkTrust
SplunkTrust

Nice thanks @PickleRick  - I rarely use single quotes with $ in so had assumed incorrectly it was the same as double quotes. 

Every day is a school day 🙂

Will

0 Karma

Mirza_Jaffar1
Loves-to-Learn
  1. yes the local directory was copied from another instance
  2. Tried to sync the directory from instance idx old to instance idx new
  3. There seem some permission issues during the migration
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Mirza_Jaffar1 

Did you copy the $SPLUNK_HOME/etc/auth/splunk.secret file from the old to the new server? This is the file that Splunk uses for encrypting sensitive configuration/secrets and is unique to each server, unless copied.

Regarding the permissions issues, did you manage to resolve these? Who are the the files/folders owned by and what user is the Splunk service running as?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

PickleRick
SplunkTrust
SplunkTrust

@Mirza_Jaffar1 Ok, so you tried to copy over the contents of old server's config to a new one, right? There were "some permission issues", right? Did you bother to check what kind of issues they were? Did you fix them?

0 Karma

Mirza_Jaffar1
Loves-to-Learn

I did check but nothing seems worked because chmod 770 is what used but chmod 550 should work! This something when usually occurs with permission.

Is there any other chmod numeric(550.775,7770) which provide same permission to the root and user?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...