Splunk Enterprise Security

ClusterManager Peer connection failed

Mirza_Jaffar1
Loves-to-Learn

what does indicates

 

06-19-2025 11:09:33.046 +0000 ERROR AesGcm [65605 MainThread] - Text decryption - error in finalizing: No errors in queue
06-19-2025 11:09:33.046 +0000 ERROR AesGcm [65605 MainThread] - AES-GCM Decryption failed!
06-19-2025 11:09:33.047 +0000 ERROR Crypto [65605 MainThread] - Decryption operation failed: AES-GCM Decryption failed!
06-19-2025 11:09:33.081 +0000 ERROR AesGcm [65605 MainThread] - Text decryption - error in finalizing: No errors in queue
06-19-2025 11:09:33.081 +0000 ERROR AesGcm [65605 MainThread] - AES-GCM Decryption failed!
06-19-2025 11:09:33.081 +0000 ERROR Crypto [65605 MainThread] - Decryption operation failed: AES-GCM Decryption failed!

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Mirza_Jaffar1 

There is no mention of SSL in the error logs so I am leaning towards an issue with the pass4SymmKey or another encrypted credential. Have you recently made any changes or installed any apps?

If you copied a local directory from another instance that contained encrypted credentials then this instance will be unable to decrypt them, this is because Splunk encrypts credentials based on its own splunk.secret file 

You can verify encrypted keys such as pass4SymmKey by using:

$SPLUNK_HOME/bin/splunk show-decrypted --value '<value>'

 

When using this you need to change the $ -> \$ otherwise Linux will think this is a variable. for example $7$abc -> \$7\$abc

Please let us know what your architecture is like, e.g. what instance is this within your architecture and if you made any recent changes.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Actually, you need to escape the dollar sign if you are not using single quotes in most shells. If you are using single quotes for strings you should not escape the contents.

:/ $ echo \$
$
:/ $ echo "\$"
$
:/ $ echo '$'
$
:/ $ echo '\$'
\$

livehybrid
SplunkTrust
SplunkTrust

Nice thanks @PickleRick  - I rarely use single quotes with $ in so had assumed incorrectly it was the same as double quotes. 

Every day is a school day 🙂

Will

0 Karma

Mirza_Jaffar1
Loves-to-Learn
  1. yes the local directory was copied from another instance
  2. Tried to sync the directory from instance idx old to instance idx new
  3. There seem some permission issues during the migration
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Mirza_Jaffar1 

Did you copy the $SPLUNK_HOME/etc/auth/splunk.secret file from the old to the new server? This is the file that Splunk uses for encrypting sensitive configuration/secrets and is unique to each server, unless copied.

Regarding the permissions issues, did you manage to resolve these? Who are the the files/folders owned by and what user is the Splunk service running as?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

PickleRick
SplunkTrust
SplunkTrust

@Mirza_Jaffar1 Ok, so you tried to copy over the contents of old server's config to a new one, right? There were "some permission issues", right? Did you bother to check what kind of issues they were? Did you fix them?

0 Karma

Mirza_Jaffar1
Loves-to-Learn

I did check but nothing seems worked because chmod 770 is what used but chmod 550 should work! This something when usually occurs with permission.

Is there any other chmod numeric(550.775,7770) which provide same permission to the root and user?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...