Why I am getting the ERROR with Splunk 9.x
distsearch.conf [distributedSearch] useIPAddrAsHost=false
distsearch.conf [distributedSearch] useIPAddrAsHost=false
Are you sure about one sslVerifyServerName = true automatically sets useIPAddressAsHost = false.
On the server sslVerifyServerName is the Splunk search head communicating to the indexers for distributed search, the sslVerifyServerName is asking for the certificate CN or SAN to match the server name returned. It's the Indexer that has to respond to the search with it's server name and not IP.
Seems like these two attributes should be on separate hosts.
I am trying to understand as well, but I don't. Right now we're on 9.0.2 and I'm now getting the below error when using this attribute, where I didn't before:
- Invalid key in stanza [distributedSearch] in /opt/splunk/etc/system/local/distsearch.conf, line 2: useIPAddrAsHost (value: false).
Thanks much in advance.
> Invalid key in stanza [distributedSearch] in /opt/splunk/etc/system/local/distsearch.conf, line 2: useIPAddrAsHost (value: false).
You get above messages because `useIPAddrAsHost` is not part of the distsearch.conf.spec file. Apart from above message, it works.
>Are you sure about one sslVerifyServerName = true automatically sets useIPAddressAsHost = false.
From 9.1 onwards.
Thank you for the clarification.