Splunk Enterprise Security

Health warning or error

domino30
Path Finder

We have a sandbox environment  with vpsphere and it works mostly just fine

we believe the time sync is corect because we have it set to use internet to auto update and for the sake or being free of errors we have disabled firewalld. (this is a  mostly linux env)

howerever we are getting the following erorrs see attached

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Whenever possible (I know that sometimes you don't have technical means) try to copy-paste actual text input in the code box (the </> symbol in the editor when you're typing in your post) or in the preformatted style instead of doing a screenshot - it's much easier to work with.

2. As @isoutamo already pointed out - those messages don't seem to have anything to do with time issues (nobody says you don't have time issues, it's just that this particular case is about network connectivity, not time). We don't know your network setup but it seems our hosts don't see each other (or the traffic is filtered somewhere).

 

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

These log entries said that you haven't connection to that another host (10.4.118.215 / No route to host).  Also those entries told to us that you have cluster configuration and this host try to replicate _audit bucket to that another peer and cannot do it.

You should test  why you haven't that tcp connection working on between these hosts. You can start with ping / traceroute then use telnet/curl and if needed even tcpdump to see what is happening.

r. Ismo

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...