<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dedicated Monitoring Console configuration problem - &amp;quot;splunk_server/splunk_server_group do not match any search peer&amp;quot; in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421263#M3571</link>
    <description>&lt;P&gt;Yes, while double checking in my lab environment found that I have also added CM as search peer on MC.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Dec 2018 10:39:31 GMT</pubDate>
    <dc:creator>harsmarvania57</dc:creator>
    <dc:date>2018-12-03T10:39:31Z</dc:date>
    <item>
      <title>Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search peer"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421258#M3566</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;I'm building a test Splunk deployment: 3 SH in cluster, 2x2 IX in multi-site cluster, 1 admin node(CM, Deployer, ...) and 1 dedicated Monitoring Console node. I have a problem with the Monitoring Console setup.&lt;BR /&gt;
I tried to follow the documentation (&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.1/DMC/Deploymentsetupsteps" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.1/DMC/Deploymentsetupsteps&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;I've added as Search peer:&lt;BR /&gt;
- all SH server&lt;BR /&gt;
- admin node (incl. Cluster Master role)&lt;/P&gt;

&lt;P&gt;I've enabled the Distributed Monitor Console, fixed instances' roles if needed. Apply.&lt;/P&gt;

&lt;P&gt;Results:&lt;BR /&gt;
- Under Overview-&amp;gt;Topology there are no Indexers listed.&lt;BR /&gt;
- There are several panels which are empty and have a warning: "Search filters specified using splunk_server/splunk_server_group do not match any search peer."&lt;/P&gt;

&lt;P&gt;What am I doing wrong? Please help me fix it.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:16:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421258#M3566</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2020-09-29T22:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search peer"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421259#M3567</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am not sure why Doc is saying that &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/DMC/Addinstancesassearchpeers"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/DMC/Addinstancesassearchpeers&lt;/A&gt;, you need to add Cluster Master as a search peer in MC. You need to point MC node to CM same as you pointed SHC members to CM to search data from Indexer Cluster (In my lab environment I have pointed MC to CM and it is automatically populating all Indexers in MC).&lt;/P&gt;

&lt;P&gt;EDIT: I have submitted feedback on that documentation, let's see what Docs team will say.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 09:10:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421259#M3567</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-12-03T09:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search peer"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421260#M3568</link>
      <description>&lt;P&gt;This Is what you are pointing to?:  "Repeat these steps for each search head, deployment server, license master, and nonclustered indexer. Do not add clustered indexers, but be sure to add clustered search heads. If you are monitoring an indexer cluster and you are hosting the monitoring console on an instance other than the cluster master, you must add the cluster master as a search peer."&lt;/P&gt;

&lt;P&gt;It says &lt;EM&gt;add&lt;/EM&gt; cm as search peer&lt;/P&gt;

&lt;P&gt;I also added the CM as Search peer to the MC node. MC also recognized it as a Cluster Master too.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 09:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421260#M3568</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2018-12-03T09:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search peer"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421261#M3569</link>
      <description>&lt;P&gt;Yes, instead of adding CM as search peer, can you please point MC node to CM same as SHC members points to CM to search data from Indexer Cluster Members (Ref. &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/SHCandindexercluster"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/SHCandindexercluster&lt;/A&gt;) &lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 09:34:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421261#M3569</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-12-03T09:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search peer"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421262#M3570</link>
      <description>&lt;P&gt;Ohh, sorry, I misunderstand you.&lt;/P&gt;

&lt;P&gt;I added MC as IX Cluster Search peer - IXs look good. But "Indexer Clustering: Status" page doesn't. I also add CM as Distributed Search peer. Now it looks good.&lt;BR /&gt;
So now: &lt;BR /&gt;
- MC is Cluster Search peer to the CM (it is added all the IX as Distributed Search peer)&lt;BR /&gt;
- On the MC CM added as Distributed Search peer&lt;/P&gt;

&lt;P&gt;Documentation does not say that at all. It looks like a support ticket will be opened...&lt;/P&gt;

&lt;P&gt;Thx.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 10:24:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421262#M3570</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2018-12-03T10:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search peer"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421263#M3571</link>
      <description>&lt;P&gt;Yes, while double checking in my lab environment found that I have also added CM as search peer on MC.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 10:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421263#M3571</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-12-03T10:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search peer"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421264#M3572</link>
      <description>&lt;P&gt;The answer is already provided but wanted to explain the logic of it.&lt;BR /&gt;
There are two ways that a distributed search is configured. One for non-clustered Indexers and one for clustered Indexers.&lt;BR /&gt;
The one for non-clustered Indexers is done via adding the Indexers as Search Peers, the other for clustered Indexers is done by adding the Search Head to the cluster via Indexer Clustering.&lt;BR /&gt;
The Monitoring Console (MC) is using the non-clustered method to connect to all instances it is monitoring (Adding those as Search Peers). The documentation assumes the MC is already connected to the cluster via the Indexer Cluster settings so it is not required that the clustered Indexers be added as standalone Indexers (Search Peers). &lt;BR /&gt;
The Cluster Master should be added as a Search Peer like the rest of the instances the MC monitors so it will be searchable as it is not searchable via the Indexer Cluster configuration.&lt;BR /&gt;
In short, both configurations are required. The Cluster Master as a Search peer and the Monitoring Console as a Search Head in the Cluster. &lt;BR /&gt;
Hope this clarifies the requirements for a standalone MC monitoring clustered Indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 11:06:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421264#M3572</guid>
      <dc:creator>zshy_splunk</dc:creator>
      <dc:date>2018-12-12T11:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search peer"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421265#M3573</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Thanks for your help here as well.&lt;BR /&gt;
Only one note:&lt;BR /&gt;
I think the documentation shouldn't assume that MC is already connected to the cluster via the Indexer Cluster settings (not listed in the prerequisites list). Not even because docs say: do not add clustered indexers as a search peer. But connecting MC to the cluster via the Indexer Cluster settings adds all the indexer as a search peer. (Correct me if I'm wrong.)&lt;/P&gt;

&lt;P&gt;So a little modification on the documentation would make this clear.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2018 15:50:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/421265#M3573</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2018-12-12T15:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/523951#M4568</link>
      <description>&lt;P&gt;Does that mean your indexer cluster would have 4 search heads in SHC(as per your lab setup)?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 15:25:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/523951#M4568</guid>
      <dc:creator>aruncp333</dc:creator>
      <dc:date>2020-10-09T15:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dedicated Monitoring Console configuration problem - "splunk_server/splunk_server_group do not match any search</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/761635#M11144</link>
      <description>&lt;P&gt;Steps of implementation MC at indexer cluster deployment infrastructure.&lt;/P&gt;&lt;P&gt;1-connect the Monitoring console to Cluster Master as a search head.&lt;/P&gt;&lt;P&gt;2-Forward all&amp;nbsp;component internal logs to indexer&amp;nbsp;&lt;SPAN&gt;(SH,LM,DS,CM) note: DS internal logs are stored locally and forwarded via selective forwarding&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3-Set search head cluster and indexer cluster labels (normally configured when u established indexer cluster)&lt;/P&gt;&lt;P&gt;4- Add all instances as search peers (SH,LM,DS,CM) except indexers which are member of clusters.&lt;/P&gt;&lt;P&gt;5-Set up the monitoring console in distributed mode as bellow&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;Log into the instance on which you want to configure the monitoring console. The instance by default is in standalone mode, unconfigured.&lt;/LI&gt;&lt;LI&gt;In Splunk Web, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Monitoring Console &amp;gt; Settings &amp;gt; General Setup&lt;/SPAN&gt;.&lt;/LI&gt;&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Distributed&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;mode.&lt;/LI&gt;&lt;LI&gt;Confirm the following:&lt;UL class=""&gt;&lt;LI&gt;The columns labeled&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;instance&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;machine&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;are populated correctly and show unique values within each column.&lt;/LI&gt;&lt;LI&gt;The server roles are correct. For example, a search head that is also a license manager must have both server roles listed. If not, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Edit &amp;gt; Edit Server Roles&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and select the correct server roles for the instance.&lt;/LI&gt;&lt;LI&gt;If you are using indexer clustering, make sure the cluster manager instance is set to the cluster manager server role. If not, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Edit &amp;gt; Edit Server Roles&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and select the correct server role.&lt;/LI&gt;&lt;LI&gt;If you are hosting the monitoring console on an instance other than the cluster manager, you must add the cluster manager instance as a search peer and configure the monitoring console instance as a search head in that cluster. See&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://help.splunk.com/?resourceId=Splunk_Indexer_Configuresearchheadwithserverconf" target="_blank" rel="noopener"&gt;Enable a search head&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Managing Indexers and Clusters of Indexers&lt;/EM&gt;.&lt;/LI&gt;&lt;LI&gt;To monitor a multisite indexer cluster, you must configure the monitoring console as a multisite search head. See&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://help.splunk.com/?resourceId=Splunk_Indexer_Multisiteconffile" target="_blank" rel="noopener"&gt;Configure the search heads&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Managing Indexers and Clusters of Indexers&lt;/EM&gt;.&lt;/LI&gt;&lt;LI&gt;Make sure anything marked as an indexer is actually an indexer.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;(Optional) Set custom groups. Custom groups are tags that map directly to distributed search groups. You might find groups useful, for example, if you have multisite indexer clustering in which each group can consist of the indexers in one location, or if you have an indexer cluster plus standalone peers. Custom groups are allowed to overlap. For example, one indexer can belong to multiple groups. See&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://help.splunk.com/?resourceId=Splunk_DistSearch_Distributedsearchgroups" target="_blank" rel="noopener"&gt;Create distributed search groups&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Distributed Search&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;manual.&lt;/LI&gt;&lt;LI&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Apply Changes&lt;/SPAN&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;the above section configuration at the screenshot shared with the comment&lt;/P&gt;&lt;P&gt;don't use the bellow configuration :&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;Edit the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;splunk_monitoring_console_assets.conf&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;etc/apps/splunk_monitoring_console/local.&lt;/LI&gt;&lt;LI&gt;Under the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;settings&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;stanza, set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;mc_auto_config&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to enable, as shown:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;[settings]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;mc_auto_config&lt;/SPAN&gt;&lt;SPAN&gt; = enabled&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Wohamed_wakkad_0-1781355017674.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/42218i386926A3CFB84EF4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Wohamed_wakkad_0-1781355017674.png" alt="Wohamed_wakkad_0-1781355017674.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jun 2026 12:55:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Dedicated-Monitoring-Console-configuration-problem-quot-splunk/m-p/761635#M11144</guid>
      <dc:creator>Wohamed_wakkad</dc:creator>
      <dc:date>2026-06-13T12:55:05Z</dc:date>
    </item>
  </channel>
</rss>

