Getting Data In

Problem with Indexer Discovery: Receiving "ERROR IndexerDiscoveryHeartbeatThread - failed heartbeart" when attempting to add a new forwarder

brdr
Contributor

Hi,

We have index clustering working fine. We have several heavy forwarders configured successfully with indexer discovery. However, when I go to add another new forwarder, I get the issue below. My steps are to add the clear text pass phrase in the outputs.conf of the forwarder. Then I restart the forwarder. From there Splunk encrypts to what is below (pass4SymmKey). Is this the correct way to add discovery to a forwarder?

[tcpout:default-autolb-group]
indexerDiscovery = cluster
useACK = true

[indexer_discovery:cluster]
master_uri = https://cluster_master:8089
pass4SymmKey = $1$19GA9JbHEqO/13Z8+c4/2Q==


10-04-2016 13:16:50.955 -0400 ERROR IndexerDiscoveryHeartbeatThread - failed heartbeat for group=default-autolb-group uri=https://cluster_master:8089/services/indexer_discovery http_response=Unauthorized
10-04-2016 13:16:52.066 -0400 WARN  TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 810 seconds.
0 Karma

stmcmahon_splun
Splunk Employee
Splunk Employee

Hello

I believe you have encountered a product defect that is fixed in 6.5.0, 6.4.4 (released last night) and 6.3.7. We have not seen the issue on anything 6.2 and earlier. Documentation is being updated to reflect that this is a fixed issue in 6.5.0.

Upgrading to 6.4.4 should fix your issue

Thank you

jmulder
New Member

Saw this yesterday and, since our Splunk cluster isn't in production yet, I performed the upgrade to 6.5.0 this morning, but still receive the same results. I've double-checked that the pass4SymmKey values match.

Any possibility that I would need to upgrade the UF as well?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...