Splunk Enterprise

We had Splunk working on a domain and joined a different domain

domino30
Path Finder

We had Splunk working on a domain and joined a different domain and then this happend to our search head cluster

weird thing.png

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for sharing.  Do you have a question?

The message says "search head cluster", but the screen shot is of an indexer cluster.  Obviously, the indexer cluster is borked.  Are you also having problems with the SHC?

Tell us more about "joined a different domain".  What exactly did you do and how did you do it?

---
If this reply helps you, Karma would be appreciated.
0 Karma

domino30
Path Finder

You are right I have got to more specific. 

our environment right now is for learning and will lead to a bigger deployment later.

currently we have an EXSI server and we had a DC, but I decided to build another dc as to not mess with the current one. after about  a month we wanted to migrate all the machines about 12 from the domain I made to the one that was previously on the Domain controller.'

Thus moving domains.  basically, how we moved our windows machine was to disjoin the domain I made and then joined the original domain.

The easy fix is deleting the machines from the exsi and rebuilding splunk.

I have had thought of deleting instance.cfg and running the clear-config command and restarting but I think I did that for all machines involved if that doesn't fix it. Is there something else I should try?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...