Splunk Search

Error from bring up the cluster captain (error=401 - call not properly authenticated)

MelnikovTimofey
New Member

I use this guide to deploy my search head cluster.
When I try to bring up the cluster captain (step 5):

/opt/splunk/bin/splunk bootstrap shcluster-captain -servers_list "https://xxx.xxx.xxx.xxx:8089,https://xxx.xxx.xxx.xxx:8089,https://xxx.xxx.xxx.xxx:8089" -auth admin:password

I get an error:

uri=https://xxx.xxx.xxx.xxx:8089/services/shcluster/member/consensus/pseudoid/last_known_state?output_mode=json, error=401 - call not properly authenticated. Is this member using the same pass4SymmKey as other members?; uri=https://xxx.xxx.xxx.xxx:8089/services/shcluster/member/consensus/pseudoid/last_known_state?output_mode=json, error=401 - call not properly authenticated. Is this member using the same pass4SymmKey as other members?;

The pass4SymmKey and the shcluster_label are the same on all cluster members in $SPLUNK_HOME$/ets/system/local/server.conf.
The stanza [shclustering]:

conf_deploy_fetch_url = https://xxx.xxx.xxx.xxx:8089
disabled = 0
mgmt_uri = https://xxx.xxx.xxx.xxx:8089
pass4SymmKey = mykey
shcluster_label = shcluster_test

The deployer is not a member of the search head cluster.
I changed the mgmt portы, but it did not help.
I can not understand what the problem is.
Thanks for the help!

0 Karma

splunker12
New Member

Make sure you restarted the Search Head after you initialized Search Head Clustering

 

0 Karma

dvb
Path Finder

Check whether your mgmt_uri is correct. It needs to point to the local system (whereas conf_deploy_fetch_url points to the Deployer).

ThomasControlwa
Path Finder

hi,
I got the same Problem.
so I solfed it with a password wich is short.
my innitial password was 121 bit long, that doesn't work.

could someone explain what the max bit of PW are?

feel free to mark this post as usefull 😄

0 Karma

MelnikovTimofey
New Member

Change pass4SymmKey with command:

splunk edit shcluster-config -secret xxxxx
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...