Splunk Enterprise

Communication problem in servers

franciscof
Explorer

Hi guys I'm receiving this error when I want to execute a search on my SH: 

franciscof_0-1599157489707.png

However, despite what that capture indicates, my license isn't expired nor exceeded, that's why this problem looks so weird.

Also, when I curl to the url (connecting from the licenser master to the IDX) I saw this error:

franciscof_1-1599157664991.png

 

This indicates to my understanding that there's a problem with the certificates installed on Splunk. Could you please help me to figure out a solution? 

 

Thanks in advance.

 

 

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

The error you have seen in curl output will be suppressed if you use -k option.

————————————
If this helps, give a like below.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

You should check the connectivity from indexer to licence master

from your indexer:

telnet yourlicensemaster 8089

————————————
If this helps, give a like below.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...