Splunk Search

Error from bring up the cluster captain (error=401 - call not properly authenticated)

MelnikovTimofey
New Member

I use this guide to deploy my search head cluster.
When I try to bring up the cluster captain (step 5):

/opt/splunk/bin/splunk bootstrap shcluster-captain -servers_list "https://xxx.xxx.xxx.xxx:8089,https://xxx.xxx.xxx.xxx:8089,https://xxx.xxx.xxx.xxx:8089" -auth admin:password

I get an error:

uri=https://xxx.xxx.xxx.xxx:8089/services/shcluster/member/consensus/pseudoid/last_known_state?output_mode=json, error=401 - call not properly authenticated. Is this member using the same pass4SymmKey as other members?; uri=https://xxx.xxx.xxx.xxx:8089/services/shcluster/member/consensus/pseudoid/last_known_state?output_mode=json, error=401 - call not properly authenticated. Is this member using the same pass4SymmKey as other members?;

The pass4SymmKey and the shcluster_label are the same on all cluster members in $SPLUNK_HOME$/ets/system/local/server.conf.
The stanza [shclustering]:

conf_deploy_fetch_url = https://xxx.xxx.xxx.xxx:8089
disabled = 0
mgmt_uri = https://xxx.xxx.xxx.xxx:8089
pass4SymmKey = mykey
shcluster_label = shcluster_test

The deployer is not a member of the search head cluster.
I changed the mgmt portы, but it did not help.
I can not understand what the problem is.
Thanks for the help!

0 Karma

splunker12
New Member

Make sure you restarted the Search Head after you initialized Search Head Clustering

 

0 Karma

dvb
Path Finder

Check whether your mgmt_uri is correct. It needs to point to the local system (whereas conf_deploy_fetch_url points to the Deployer).

ThomasControlwa
Path Finder

hi,
I got the same Problem.
so I solfed it with a password wich is short.
my innitial password was 121 bit long, that doesn't work.

could someone explain what the max bit of PW are?

feel free to mark this post as usefull 😄

0 Karma

MelnikovTimofey
New Member

Change pass4SymmKey with command:

splunk edit shcluster-config -secret xxxxx
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...