Splunk Enterprise Security

Health warning or error

domino30
Path Finder

We have a sandbox environment  with vpsphere and it works mostly just fine

we believe the time sync is corect because we have it set to use internet to auto update and for the sake or being free of errors we have disabled firewalld. (this is a  mostly linux env)

howerever we are getting the following erorrs see attached

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Whenever possible (I know that sometimes you don't have technical means) try to copy-paste actual text input in the code box (the </> symbol in the editor when you're typing in your post) or in the preformatted style instead of doing a screenshot - it's much easier to work with.

2. As @isoutamo already pointed out - those messages don't seem to have anything to do with time issues (nobody says you don't have time issues, it's just that this particular case is about network connectivity, not time). We don't know your network setup but it seems our hosts don't see each other (or the traffic is filtered somewhere).

 

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

These log entries said that you haven't connection to that another host (10.4.118.215 / No route to host).  Also those entries told to us that you have cluster configuration and this host try to replicate _audit bucket to that another peer and cannot do it.

You should test  why you haven't that tcp connection working on between these hosts. You can start with ping / traceroute then use telnet/curl and if needed even tcpdump to see what is happening.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...