Splunk Enterprise

Problem with indexer discovery on AIX using Universal Forwarder 8.1.3

las
Contributor

Hi.

I would like to know if anybode else had this issue.

We upgraded our UF on AIX to 8.1.3 from 8.0.4, following the guidelines from Splunk.

We have set outputs.conf to use indexer discovery.

After the upgrade we saw these message:

  • ERROR IndexerDiscoveryHeartbeatThread - Error in Indexer Discovery communication. Verify that the pass4SymmKey set under [indexer_discovery:prod] in 'outputs.conf' matches the same setting under [indexer_discovery] in 'server.conf' on the Cluster Master. [uri=https://xxxx:8089/services/indexer_discovery http_code=502 http_response="OK"]

The pass4SymmKey has not changed during the upgrade.

We changed the configuration to bypass indexer discovery, and that got data flowing into the system again.

 

Kind regards

Lars Søndergaard

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Is your CM already at least level 8.1.3?
How you did your UF upgrade (just upgrade or remove/install)?
r. Ismo
0 Karma

las
Contributor

Hi.

Yes, the CM was upgraded to 8.1.3 prior to the upgrade of the UFs. It was just an upgrade, so no remove.

kind regards

Lars

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Have you try to update pass4SymmKey already? Even it has worked earlier there could be happened something which has corrupted it or change splunk.secret on UF.
0 Karma

las
Contributor

Yes, I did try to update the pass4SymmKey, that didn't work.

It seems this problem is only on the AIX part, we have succesfully upgraded both Linux and Windows so it is not a general bug.

Kind regards

las

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Probably you should raise a ticket to splunk support.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...