<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to see Internal logs which are sent from Search Head to Indexer? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324348#M12126</link>
    <description>&lt;P&gt;Yup. I dont see SH mentioned in the host field. I should have mentioned that in my question. &lt;/P&gt;</description>
    <pubDate>Wed, 06 Sep 2017 10:59:42 GMT</pubDate>
    <dc:creator>varad_joshi</dc:creator>
    <dc:date>2017-09-06T10:59:42Z</dc:date>
    <item>
      <title>How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324344#M12122</link>
      <description>&lt;P&gt;I followed the steps mentioned on below link to send internal logs from SH to indexer.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.0/DistSearch/Forwardsearchheaddata"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.0/DistSearch/Forwardsearchheaddata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Now I am looking for a way to check and validate that I am receiving internal logs from SH to my indexer. How do I do that? &lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 10:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324344#M12122</guid>
      <dc:creator>varad_joshi</dc:creator>
      <dc:date>2017-09-06T10:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324345#M12123</link>
      <description>&lt;P&gt;This should do it:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host=searchheadhostname
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If there are events returned, it should be working.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 10:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324345#M12123</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-09-06T10:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324346#M12124</link>
      <description>&lt;P&gt;Hi varad_joshi,&lt;BR /&gt;
did you tried&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host=SH_hostename
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;?&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 10:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324346#M12124</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-06T10:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324347#M12125</link>
      <description>&lt;P&gt;Jinx!&lt;/P&gt;

&lt;P&gt;@cusello - E una cosa Americana di dirlo quando diciamo la stessa cosa allo stesso tempo. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Auguri!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 10:50:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324347#M12125</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-09-06T10:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324348#M12126</link>
      <description>&lt;P&gt;Yup. I dont see SH mentioned in the host field. I should have mentioned that in my question. &lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 10:59:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324348#M12126</guid>
      <dc:creator>varad_joshi</dc:creator>
      <dc:date>2017-09-06T10:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324349#M12127</link>
      <description>&lt;P&gt;I dont see SH mentioned in the host field. I should have mentioned that in my question. So events are not being moved to indexer. Right?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 11:00:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324349#M12127</guid>
      <dc:creator>varad_joshi</dc:creator>
      <dc:date>2017-09-06T11:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324350#M12128</link>
      <description>&lt;P&gt;Sounds like that is correct.&lt;/P&gt;

&lt;P&gt;Be sure you are forwarding your events to the indexers. You can do it in the GUI, too. If you don't set it up to forward, then they will stay on the SH. It's like you would do on an HF.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 11:07:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324350#M12128</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-09-06T11:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324351#M12129</link>
      <description>&lt;P&gt;Have a look to this url and review your config according to that:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Forwardsearchheaddata"&gt;http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Forwardsearchheaddata&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps you&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 11:11:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324351#M12129</guid>
      <dc:creator>Javip</dc:creator>
      <dc:date>2017-09-06T11:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324352#M12130</link>
      <description>&lt;P&gt;OK thanks!&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 11:12:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324352#M12130</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-09-06T11:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324353#M12131</link>
      <description>&lt;P&gt;I used that URL to start forwarding internal logs. Now I want to validate the logs are coming to indexer. &lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 07:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324353#M12131</guid>
      <dc:creator>varad_joshi</dc:creator>
      <dc:date>2017-09-07T07:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324354#M12132</link>
      <description>&lt;P&gt;Ahh, ok, I thought you were wrong with Splunk version or so ...&lt;/P&gt;

&lt;P&gt;The logs are not coming to your indexer, but are they still accesible in your SH? Have you read them if they show you some kind of problem/error?&lt;BR /&gt;
Have you checked communication in port 9997 between SH and indexers?&lt;/P&gt;

&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 10:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324354#M12132</guid>
      <dc:creator>Javip</dc:creator>
      <dc:date>2017-09-07T10:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to see Internal logs which are sent from Search Head to Indexer?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324355#M12133</link>
      <description>&lt;P&gt;I think I finally understand what you need. &lt;/P&gt;

&lt;P&gt;If you look at the field &lt;CODE&gt;splunk_server&lt;/CODE&gt; on the data from the search that cusello and I answered with, that will tell you which host the data was indexed on. If the field has your indexer, then it is working. If it is the search head, then it is not.&lt;/P&gt;

&lt;P&gt;Hopefully I understood your dilemma correctly.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 12:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-Internal-logs-which-are-sent-from-Search-Head-to/m-p/324355#M12133</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-09-07T12:17:02Z</dc:date>
    </item>
  </channel>
</rss>

