Splunk Enterprise

Ingest actions implementation

zzubidah
Loves-to-Learn Lots

Hello,

I have a distributed Splunk architecture and I am trying to optimise/trim the received logs using Ingest actions features. However, I have the below error :

- I tried to create new rule set on the Heavey forwarder and indexer , but it returned with the error message "this endpoint will reject all requests until pass4SymmKey has been properly set."

So, I want to check where should I implement this feature on Indexer or HF? and is there any pre-request to implement it?

Labels (1)
0 Karma

zzubidah
Loves-to-Learn Lots

 

 

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust
0 Karma

zzubidah
Loves-to-Learn Lots

Hello Rick,

I tried Live Capture, but it gave the same error, I think the issue is related to pass4SymmKey.

pass4SymmKey.JPG

0 Karma

dural_yyz
Motivator

Your outputs.conf will need to match the pass4SymmKey set on the CM and IDX layer - since you are trying to reduce existing logs I want to assume that was already done but I'm not certain based on your explanation of the error message.

Since the metrics logs are abundant and it's hard to think that HF performance matters at 30 seconds frequency I would recommend changing the collection interval and keep the rest if possible.

0 Karma

zzubidah
Loves-to-Learn Lots

Hello Dural,

I think the issue is related to pass4SymmKey, have you ever change that key? If so, please share what files should be changed? and if you have any guideline for that, this will be much helpful.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...