<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Indexer not forwarding its own internal logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500954#M85330</link>
    <description>&lt;P&gt;Do we need to set up anything specific for an indexer internal logs to see .We just added the indexer and I can see logs coming from that indexer from diff inputs but not its own internal logs.I can see its won logs if I log into the indexer.How do I see them on the search head&lt;/P&gt;</description>
    <pubDate>Tue, 04 Feb 2020 19:18:21 GMT</pubDate>
    <dc:creator>vrmandadi</dc:creator>
    <dc:date>2020-02-04T19:18:21Z</dc:date>
    <item>
      <title>Indexer not forwarding its own internal logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500954#M85330</link>
      <description>&lt;P&gt;Do we need to set up anything specific for an indexer internal logs to see .We just added the indexer and I can see logs coming from that indexer from diff inputs but not its own internal logs.I can see its won logs if I log into the indexer.How do I see them on the search head&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 19:18:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500954#M85330</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2020-02-04T19:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer not forwarding its own internal logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500955#M85331</link>
      <description>&lt;P&gt;Are you running Indexer Cluster ? I have seen this type of issue (not remember exact issue ) and it was configuration issue in &lt;CODE&gt;distsearch.conf&lt;/CODE&gt;, someone configured &lt;CODE&gt;distsearch.conf&lt;/CODE&gt; however it was not require because our SH was pointing to Cluster Master.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 20:45:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500955#M85331</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-02-04T20:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer not forwarding its own internal logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500956#M85332</link>
      <description>&lt;P&gt;Is it happening only for that one indexer OR all the indexers?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 21:14:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500956#M85332</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-02-04T21:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer not forwarding its own internal logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500957#M85333</link>
      <description>&lt;P&gt;Hello @somesoni2  .It is happening only for one indexer .We have a total of 3 indexers in our cluster&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 16:28:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500957#M85333</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2020-02-06T16:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer not forwarding its own internal logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500958#M85334</link>
      <description>&lt;P&gt;Yes it is indexer cluster .Should I look into anything specific?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 16:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500958#M85334</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2020-02-06T16:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer not forwarding its own internal logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500959#M85335</link>
      <description>&lt;P&gt;Do you have &lt;CODE&gt;distsearch.conf&lt;/CODE&gt; on Search Head ? Are your Search Head pointing to Cluster Master ?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 16:32:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500959#M85335</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-02-06T16:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer not forwarding its own internal logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500960#M85336</link>
      <description>&lt;P&gt;Yes its there but there is nothing init regarding the CM. Yes the SH is pointing to the Cluster Master&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 17:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500960#M85336</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2020-02-06T17:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer not forwarding its own internal logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500961#M85337</link>
      <description>&lt;P&gt;Not made any changes.I see the data now&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 18:00:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500961#M85337</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2020-02-06T18:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer not forwarding its own internal logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500962#M85338</link>
      <description>&lt;P&gt;Not made any changes.I see the data now.Strange!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 18:01:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-not-forwarding-its-own-internal-logs/m-p/500962#M85338</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2020-02-06T18:01:03Z</dc:date>
    </item>
  </channel>
</rss>

