<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deployment Monitor not getting data to the summary_* indexes in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72165#M22483</link>
    <description>&lt;P&gt;Following the trail back from the saved search "All sourcetypes regenerator" the macro &lt;CODE&gt;sourcetype_metrics&lt;/CODE&gt; didn't work.  Which led me to:  index=_internal source=*license_usage.log, which also had no data.  The tailing processor says the file is being read (100%), but can't currently find the data.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 11:24:45 GMT</pubDate>
    <dc:creator>mikelanghorst</dc:creator>
    <dc:date>2020-09-28T11:24:45Z</dc:date>
    <item>
      <title>Deployment Monitor not getting data to the summary_* indexes</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72161#M22479</link>
      <description>&lt;P&gt;When I go into the DeploymentMonitor app to All Sourcetypes, the reports show No Results.  In fact searching:  index=summary_sourcetypes also shows no data.  So looking at my search head and indexers, I have no data in $SPLUNK_DB/summary_sourcetypes at all.&lt;/P&gt;

&lt;P&gt;When I clicked on the "flush and backfill summary indexes" seems to do little more than creating a very large number of jobs in the dispatch directory on the search head.&lt;/P&gt;

&lt;P&gt;What am I missing here?  The indexes are created on the indexers and the search head, and other data is forwarded just fine from the search head to the indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:24:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72161#M22479</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T11:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Monitor not getting data to the summary_* indexes</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72162#M22480</link>
      <description>&lt;P&gt;Can you verify that your issue is not the same as &lt;A href="http://splunk-base.splunk.com/answers/34532/deployment-monitor-issue-no-data-in-summary-indexes"&gt;http://splunk-base.splunk.com/answers/34532/deployment-monitor-issue-no-data-in-summary-indexes&lt;/A&gt; ?&lt;/P&gt;

&lt;P&gt;If not, are you running search head pooling?  What version of Splunk are you running?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2012 00:20:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72162#M22480</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-02-16T00:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Monitor not getting data to the summary_* indexes</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72163#M22481</link>
      <description>&lt;P&gt;/app/splunk/var/log/splunk is indeed enabled, and I can search for splunkd messages.  But not seeing any messages related to summary_sourcetypes in splunkd.log.&lt;/P&gt;

&lt;P&gt;I'm running 4.2.3 with no search head pooling.  Looking at each summary_* index:&lt;BR /&gt;
summary_forwarders - have buckets here&lt;BR /&gt;
summary_hosts - no buckets&lt;BR /&gt;
summary_indexers - have buckets here&lt;BR /&gt;
summary_pools - no buckets&lt;BR /&gt;
summary_sources - no buckets&lt;BR /&gt;
summary_sourcetypes - no buckets&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72163#M22481</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T11:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Monitor not getting data to the summary_* indexes</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72164#M22482</link>
      <description>&lt;P&gt;Hmm, maybe it's just the saved searches aren't scheduled to feed these reports?  I figured if there was a default report that the required search would be scheduled by default.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2012 17:12:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72164#M22482</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-02-16T17:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Monitor not getting data to the summary_* indexes</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72165#M22483</link>
      <description>&lt;P&gt;Following the trail back from the saved search "All sourcetypes regenerator" the macro &lt;CODE&gt;sourcetype_metrics&lt;/CODE&gt; didn't work.  Which led me to:  index=_internal source=*license_usage.log, which also had no data.  The tailing processor says the file is being read (100%), but can't currently find the data.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:24:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72165#M22483</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T11:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Monitor not getting data to the summary_* indexes</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72166#M22484</link>
      <description>&lt;P&gt;Just realized I didn't actually answer your question alex.  The sources are enabled.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2012 19:25:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72166#M22484</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-02-16T19:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Monitor not getting data to the summary_* indexes</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72167#M22485</link>
      <description>&lt;P&gt;With the assistance of Genti on IRC, we found the issue:&lt;/P&gt;

&lt;P&gt;I'd configured the Search Head as a SplunkForwarder, to send the data to my indexers.  This wasn't routing the license_usage file to the indexers, indicated by the following in "cmd btool outputs list":&lt;/P&gt;

&lt;P&gt;forwardedindex.1.blacklist = _.*&lt;/P&gt;

&lt;P&gt;I've added a monitor for that specific file to route it, adding:&lt;BR /&gt;
[monitor://$SPLUNK_HOME/var/log/splunk/license_usage.log]&lt;BR /&gt;
_TCP_ROUTING = *&lt;BR /&gt;
index = _internal&lt;/P&gt;

&lt;P&gt;Now my searches are returning data for this source&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:24:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72167#M22485</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T11:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Monitor not getting data to the summary_* indexes</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72168#M22486</link>
      <description>&lt;P&gt;I'm putting my name here just to:&lt;BR /&gt;&lt;BR /&gt;
Splunk &amp;gt; Trolling for upgoats!&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2012 23:49:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-Monitor-not-getting-data-to-the-summary-indexes/m-p/72168#M22486</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2012-02-16T23:49:22Z</dc:date>
    </item>
  </channel>
</rss>

