<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201477#M7511</link>
    <description>&lt;P&gt;We are attempting to deploy the Distributed Management Console, but are not having success.  I have reviewed all of the previous submissions, but am not finding a solution to our challenge.   We are running Splunk 6.3.2 in a distributed environment.  I have followed the DMC deployment doc for the DMC prerequisites, but have obviously missed something.  All nodes have been added in the DMC as Search Peers, _introspection_generator configurations have been verified, platform instrumentation has been enabled.  &lt;/P&gt;

&lt;P&gt;The problem: When accessing the DMC console, there is no data for any of the Search Heads in any of the DMC screens.  All other systems appear, and with report content.&lt;/P&gt;

&lt;P&gt;I have an environment consisting of 14 nodes: &lt;BR /&gt;
4 indexers&lt;BR /&gt;
4 forwarders&lt;BR /&gt;
3 search heads&lt;BR /&gt;
3 management servers: Deployment Svr, Search Head Cluster Deployer, Indexer Cluster Master/DMC&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 09:24:24 GMT</pubDate>
    <dc:creator>tlmayes</dc:creator>
    <dc:date>2020-09-29T09:24:24Z</dc:date>
    <item>
      <title>When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201477#M7511</link>
      <description>&lt;P&gt;We are attempting to deploy the Distributed Management Console, but are not having success.  I have reviewed all of the previous submissions, but am not finding a solution to our challenge.   We are running Splunk 6.3.2 in a distributed environment.  I have followed the DMC deployment doc for the DMC prerequisites, but have obviously missed something.  All nodes have been added in the DMC as Search Peers, _introspection_generator configurations have been verified, platform instrumentation has been enabled.  &lt;/P&gt;

&lt;P&gt;The problem: When accessing the DMC console, there is no data for any of the Search Heads in any of the DMC screens.  All other systems appear, and with report content.&lt;/P&gt;

&lt;P&gt;I have an environment consisting of 14 nodes: &lt;BR /&gt;
4 indexers&lt;BR /&gt;
4 forwarders&lt;BR /&gt;
3 search heads&lt;BR /&gt;
3 management servers: Deployment Svr, Search Head Cluster Deployer, Indexer Cluster Master/DMC&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:24:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201477#M7511</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2020-09-29T09:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201478#M7512</link>
      <description>&lt;P&gt;There are two possible reasons:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;you didn't switch DMC to distributed mode in DMC General Setup page. &lt;/LI&gt;
&lt;LI&gt;you didn't forward all search heads' internal logs to indexers. &lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The first reason is more likely to be your case, otherwise the DMC dashboards' Snapshot section should work because it doesn't rely on internal logs. In addition, please verify that the search head names showing up in the Instance dropdown menu on the top of each dashboard. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 16:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201478#M7512</guid>
      <dc:creator>ykou_splunk</dc:creator>
      <dc:date>2016-04-13T16:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201479#M7513</link>
      <description>&lt;P&gt;Appreciate the quick turnaround on a response.  I failed to add in my post that I: Switched from "standalone" to "distributed" on the DMC in "Settings &amp;gt; Distributed Management Console &amp;gt; Settings &amp;gt; General Setup".  So this is done and confirmed, again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;On the second, have always thought this might be the case, but not quite sure how to verify other than performing a search in index=*_ and filtering for the Search Heads (which by the way returns nothing).   Configured "outputs.conf" on the Search Heads per the DMC docs with the server line pointing to my Indexers. &lt;/P&gt;

&lt;P&gt;Regarding the dashboards and the "Snapshot", I assume you are referring to the "Overview".  Nothing there, or within any of the dropdowns under "Search", or anywhere else that is reporting on "Search" data.&lt;/P&gt;

&lt;P&gt;Regarding the Instances dropdown in DMC, the search heads do NOT show up here.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 17:29:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201479#M7513</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2016-04-13T17:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201480#M7514</link>
      <description>&lt;P&gt;when you switched to "distributed" mode, do you see a table of instances listed on that page? your search heads should appear in that table. Also, make sure they have the "Search Head" role. Then click the "Apply changes" button on top right corner on that page. &lt;/P&gt;

&lt;P&gt;Please note assigning the right role and clicking the "Apply changes" button are required steps. Once these steps are done, at least the search heads should show up in the Instances dropdown. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 18:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201480#M7514</guid>
      <dc:creator>ykou_splunk</dc:creator>
      <dc:date>2016-04-13T18:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201481#M7515</link>
      <description>&lt;P&gt;Yes, when I switched to distributed mode the Search Heads did (and do) show up listed as instances, and the column Search Head Cluster(s) was populated as well.&lt;/P&gt;

&lt;P&gt;The following details appear&lt;BR /&gt;
&lt;STRONG&gt;Server Role&lt;/STRONG&gt;: KV Store / Search Head&lt;BR /&gt;
&lt;STRONG&gt;Search Head Cluster(s):&lt;/STRONG&gt; &lt;BR /&gt;
&lt;STRONG&gt;Monitoring:&lt;/STRONG&gt; Enabled&lt;BR /&gt;
&lt;STRONG&gt;State:&lt;/STRONG&gt; Configured&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 18:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201481#M7515</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2016-04-13T18:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201482#M7516</link>
      <description>&lt;P&gt;Clarification to previous post: The DMC was already in Distributed mode, I did not change it into Distributed mode, and although the Search Heads appear as described (already did) they still do not appear in the Distributed Management Console in any of the reporting.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 20:24:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201482#M7516</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2016-04-13T20:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201483#M7517</link>
      <description>&lt;P&gt;when you click the "apply changes" button, is there a dialog popup showing the saving progress and finally shows a confirmation that the changes have been saved? &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 21:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201483#M7517</guid>
      <dc:creator>ykou_splunk</dc:creator>
      <dc:date>2016-04-13T21:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201484#M7518</link>
      <description>&lt;P&gt;Seems I do not have enough "carma" points to post an attachment &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;
The dialog does appear, and completes the process.  Each time I have tried this, I receive slightly different errors.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;This time:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;"At least one of your instances is a deployment server plus other non-deployer roles.  We recommend only deployer roles per deployment server"&lt;/P&gt;

&lt;P&gt;"At least one of your instances is a search head deployer plus other non-deployer roles.  We recommend only deployer roles per search head deployer"&lt;/P&gt;

&lt;P&gt;"At least one of your instances is an indexer plus other roles.  We recommend only one role per indexer"&lt;/P&gt;

&lt;P&gt;"At lease one of your instances is a search head deployer without a search head cluster label.  We recommendyou edit these instances to set their search head cluster labels"&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Roles as displayed in the DMC "Setup Screen"&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;This Instance (the DMC node)&lt;/STRONG&gt;&lt;BR /&gt;
 - Instance: Cluster Master / License Master / Search Head&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Remote instances&lt;/STRONG&gt;&lt;BR /&gt;
 - Instance 1:  Indexer (indexer cluster)&lt;BR /&gt;
 - Instance 2:  Indexer (indexer cluster)&lt;BR /&gt;
 - Instance 3:  Indexer (indexer cluster)&lt;BR /&gt;
 - Instance 4:  Indexer (indexer cluster)&lt;BR /&gt;
 - Instance 5:  Deployment Svr / Indexer / SHC Deployer&lt;BR /&gt;
 - Instance 6:  Deployment Svr / Indexer&lt;BR /&gt;
 - Instance 7:  KV Store / Search Head (search head cluster) (index cluster)&lt;BR /&gt;
 - Instance 8:  KV Store / Search Head (search head cluster) (index cluster)&lt;BR /&gt;
 - Instance 9:  KV Store / Search Head (search head cluster) (index cluster)&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 12:12:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201484#M7518</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2016-04-14T12:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: When accessing the Distributed Management Console, why is there no data for any search heads in our distributed search environment?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201485#M7519</link>
      <description>&lt;P&gt;I've found on my dedicated DMC instance if I add search head as a search peer, it shows up immediately and classifies it appropriately as a search head. A better setup would be to prompt users for endpoints to monitor.&lt;/P&gt;

&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 04:34:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/When-accessing-the-Distributed-Management-Console-why-is-there/m-p/201485#M7519</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2016-12-15T04:34:23Z</dc:date>
    </item>
  </channel>
</rss>

