Deployment Architecture

Error: Unable to distribute to peer because peer has status ="Authentication failed

keerthana_k
Communicator

I am getting error "Unable to distribute to peer named lonrs10457 at uri https://SPLUNK-IDX1:8089 because peer has status ="Authentication failed"" in our Search Head while executing any search. I have a distributed search setup. I have checked the status under Manager » Distributed search » Search peers>. Only the Indexer is shown as up and running with Status=Up and Replication status=Succesful.

Tags (1)
0 Karma

Simeon
Splunk Employee
Splunk Employee

That error typically means that you cannot search the remote peer. This can be due to privileges against the remote peer or a problem with how you have added it as a peer. The authentication to a remote peer is tokenized, so if it previously worked then it is likely that there may be a connectivity problem or change in that token.

0 Karma

MHibbin
Influencer

you also have to make sure you are not using the default admin password (i.e. changeme), as this will not work... but then I'd assume you are not if you have already added it... but then again, assume nothing 🙂

0 Karma

kristian_kolb
Ultra Champion

have you tried to remove the search peer and adding it back again? Note that you need the proper credentials for the splunkd (i.e. indexer) you want to add back as a search peer.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...