<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: index=_interospection in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582041#M25217</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241514"&gt;@mitali&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;from the Splunk menu on Each Splunk server (except Indexers): [Settings -- Forwarding and Receiving]:&lt;/P&gt;&lt;P&gt;[Forwarding Default -- Save ]&lt;/P&gt;&lt;P&gt;[Configure Forwarding -- New Forwarding host] add indexers&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jan 2022 16:19:56 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-01-21T16:19:56Z</dc:date>
    <item>
      <title>index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582022#M25212</link>
      <description>&lt;P&gt;Unable to see my host in index=_interospection /_internal&amp;nbsp;&lt;/P&gt;&lt;P&gt;after runing the above query in the same host I can't see the hostname.&lt;/P&gt;&lt;P&gt;Unable to see host ES&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mitali_0-1642779910440.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17647iC43E4AF7F7124BB7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mitali_0-1642779910440.png" alt="mitali_0-1642779910440.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 15:48:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582022#M25212</guid>
      <dc:creator>mitali</dc:creator>
      <dc:date>2022-01-21T15:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582026#M25213</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241514"&gt;@mitali&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand:&lt;/P&gt;&lt;P&gt;you runned a search on _internal and in the result list there isn't the hostname of the ES Search Head, is it correct?&lt;/P&gt;&lt;P&gt;Have you this condition also enlarging the time period of your Search?&lt;/P&gt;&lt;P&gt;A very stupid question: did you checked the hostname of your Search Head on the server.conf file ?&lt;/P&gt;&lt;P&gt;Anyway, sometimes _internal logs indexing is delayed when the Indexers are very busy, but you should have many warning messages about this.&lt;/P&gt;&lt;P&gt;For this reason I hint to check the hostname.&lt;/P&gt;&lt;P&gt;Please share more details.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 15:56:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582026#M25213</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-21T15:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582029#M25214</link>
      <description>&lt;P&gt;Yes running index=_internal on ES search head but not showing ES host name&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes the hostname in server.conf file is correct.&lt;/P&gt;&lt;P&gt;yes even after expanding timerange hostname is not available.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 16:01:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582029#M25214</guid>
      <dc:creator>mitali</dc:creator>
      <dc:date>2022-01-21T16:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582031#M25215</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241514"&gt;@mitali&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;did you forwarded the Search Heads logs to the Indexers, as hinted by Splunk best practices?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 16:05:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582031#M25215</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-21T16:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582037#M25216</link>
      <description>&lt;P&gt;Can you Please tell me how to do that?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 16:08:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582037#M25216</guid>
      <dc:creator>mitali</dc:creator>
      <dc:date>2022-01-21T16:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582041#M25217</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241514"&gt;@mitali&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;from the Splunk menu on Each Splunk server (except Indexers): [Settings -- Forwarding and Receiving]:&lt;/P&gt;&lt;P&gt;[Forwarding Default -- Save ]&lt;/P&gt;&lt;P&gt;[Configure Forwarding -- New Forwarding host] add indexers&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 16:19:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582041#M25217</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-21T16:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582048#M25218</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mitali_0-1642782453954.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17649iCB10466B3415C7DD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mitali_0-1642782453954.png" alt="mitali_0-1642782453954.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;indexers are already aaded&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mitali_1-1642782494792.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17650iAB5DF089B7A6F9C8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mitali_1-1642782494792.png" alt="mitali_1-1642782494792.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;this is correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 16:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582048#M25218</guid>
      <dc:creator>mitali</dc:creator>
      <dc:date>2022-01-21T16:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582051#M25219</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241514"&gt;@mitali&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Check if there's the port in the destination: "indexer_name:9997".&lt;/P&gt;&lt;P&gt;Then, remember to click "Save" in the "Default configuration", it will ask you a restart.&lt;/P&gt;&lt;P&gt;Then, On your indexers, do you receive also from Forwarders or only by syslog?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 16:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582051#M25219</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-21T16:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582054#M25220</link>
      <description>&lt;P&gt;everything is correct just that hostname is not showing up&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 16:59:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582054#M25220</guid>
      <dc:creator>mitali</dc:creator>
      <dc:date>2022-01-21T16:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582061#M25221</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Error [00000080] Instance name "BCCS-P25ES." REST interface to peer is taking longer than 5 seconds to respond on https. Peer may be over subscribed or misconfigured. Check var/log/splunk/splunkd_access.log on the peer Last Connect Time:2022-01-21T22:45:45.000+05:30; Failed 11 out of 11 times.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;showing this error in monitoring console.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 17:20:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582061#M25221</guid>
      <dc:creator>mitali</dc:creator>
      <dc:date>2022-01-21T17:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582125#M25222</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241514"&gt;@mitali&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;try to use Ip address instead hostname in the "Add indexers" form:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;10.10.10.10:9997
10.10.10.11:9997&lt;/LI-CODE&gt;&lt;P&gt;and then (using telnet) check if the route between SH and IND is open:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;telnet &amp;lt;ip_Indexer&amp;gt; 9997&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jan 2022 07:05:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582125#M25222</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-22T07:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582412#M25227</link>
      <description>&lt;P&gt;Problem sloved solution was to create outputs.conf on Search head&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 16:10:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582412#M25227</guid>
      <dc:creator>mitali</dc:creator>
      <dc:date>2022-01-25T16:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: index=_interospection</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582418#M25228</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241514"&gt;@mitali&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;really strange: using the GUI as I hinted has the same result!&lt;/P&gt;&lt;P&gt;Anyway, if you solved, please accept the answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the Contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 16:58:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/index-interospection/m-p/582418#M25228</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-25T16:58:30Z</dc:date>
    </item>
  </channel>
</rss>

