<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Warning when searching without results in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510071#M142594</link>
    <description>&lt;P&gt;thanks again, I don't see the field you are referring to.&amp;nbsp; But I see there are some fields missing when comparing the log from another a server that succeeds the distuributed search and this where it fails.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;searchProviders on the one it works, contains the name of the searchpeer, on my server where it fails it contains the name of the server itself.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Field that are missing : remoteSearchLogs, peerNameList, they show the name of the searchpeer on the server it works, the fields are missing on the sever where it does not work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2020 17:01:28 GMT</pubDate>
    <dc:creator>hendriks</dc:creator>
    <dc:date>2020-07-20T17:01:28Z</dc:date>
    <item>
      <title>Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510041#M142581</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a simple distributed search config on a windows host, 1 SH, 1 IDX and 1 License server. Running a search from the SH give me a warning&amp;nbsp; : "&lt;SPAN&gt;Search filters specified using splunk_server/splunk_server_group do not match any search peer." And the search does not return any results.&amp;nbsp; (searching for index=_internal)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The answers found on this same topic over here do not seem to solve the problem for me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recreated the user and the role, no success, I recreated the search peer, without success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Status under distributed search is healthy and replication status is Successful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions what i could do to get distributed search up and running?&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 14:11:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510041#M142581</guid>
      <dc:creator>hendriks</dc:creator>
      <dc:date>2020-07-20T14:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510045#M142584</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/39021"&gt;@hendriks&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am assuming you are running the search on SH.&lt;/P&gt;&lt;P&gt;Are you forwarding all the data from SH to Indexer?&lt;/P&gt;&lt;P&gt;Did you add search peer on search head? settings -&amp;gt; Distributed search -&amp;gt; search peers -&amp;gt; add new (you should add your indexer here)&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 14:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510045#M142584</guid>
      <dc:creator>anilchaithu</dc:creator>
      <dc:date>2020-07-20T14:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510051#M142588</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/204579"&gt;@anilchaithu&lt;/a&gt;&amp;nbsp; thank&amp;nbsp; you for your reply, all you suggested i did.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes i did run the search from the SH, thats where i see the warning, in the search Job inspector:&lt;/P&gt;&lt;P&gt;The following messages were returned by the search subsystem:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;warn :&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="text"&gt;Search filters specified using splunk_server/splunk_server_group do not match any search peer.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;I'm forwarding all logs to the indexer and can see/search for them there (index=_internal host=shserver.local) and get results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added the indexer as searchpeer,&amp;nbsp; when looking in&amp;nbsp; myserver:8000/en-GB/manager/splunk_monitoring_console/search/distributed/peers for this server (the only one in the list) the state is up,&amp;nbsp; health status is healthy and the replication status Successful, cluster label is none.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 15:26:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510051#M142588</guid>
      <dc:creator>hendriks</dc:creator>
      <dc:date>2020-07-20T15:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510059#M142589</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/39021"&gt;@hendriks&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check search.log for final search distributed to search peers. It will indicate the final search (along with search filters)&lt;/P&gt;&lt;P&gt;my guess is the splunk_server search filter is not matching with the indexer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 16:34:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510059#M142589</guid>
      <dc:creator>anilchaithu</dc:creator>
      <dc:date>2020-07-20T16:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510071#M142594</link>
      <description>&lt;P&gt;thanks again, I don't see the field you are referring to.&amp;nbsp; But I see there are some fields missing when comparing the log from another a server that succeeds the distuributed search and this where it fails.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;searchProviders on the one it works, contains the name of the searchpeer, on my server where it fails it contains the name of the server itself.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Field that are missing : remoteSearchLogs, peerNameList, they show the name of the searchpeer on the server it works, the fields are missing on the sever where it does not work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 17:01:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510071#M142594</guid>
      <dc:creator>hendriks</dc:creator>
      <dc:date>2020-07-20T17:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510097#M142645</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/204579"&gt;@anilchaithu&lt;/a&gt;&amp;nbsp;thanks, I was able to solve it now. I made the server standalone again, so removed forwarding of logs, removed the search pear. Doing a search still gave the same problem so i decided to&amp;nbsp; add the indexserver role. After the restart the localsearch&amp;nbsp; worked. It gave results on index _interal. After this i added back the Searchpeer, forwarding of logs and as last I removed the Indexer role.&amp;nbsp; A restart later and all still worked.&amp;nbsp; So don't know what really was wrong but I think some pff the configs was wonkie somehow..&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reverting the searchhead to an almost standalone server and back to a distributed searchhead fixed it in the end.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this will help others who run in this unclear to solve this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 19:04:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/510097#M142645</guid>
      <dc:creator>hendriks</dc:creator>
      <dc:date>2020-07-20T19:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/748482#M241998</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/39021"&gt;@hendriks&lt;/a&gt;&amp;nbsp;,&amp;nbsp; this is an old post, but can you remember the actions to add t&lt;SPAN&gt;he indexserver role ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 09:00:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/748482#M241998</guid>
      <dc:creator>_olivier_</dc:creator>
      <dc:date>2025-06-23T09:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/748485#M241999</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257739"&gt;@_olivier_&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;don't attach a new question on an old one, even if on the same topic: open a new request, so you will be more sure to receive an answer.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 09:07:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/748485#M241999</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-06-23T09:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/748487#M242000</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;_olivier_,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Yes, off course when on your server go to the monitoring console, there under the menu setting, select "general setup" and there you can set the server roles.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 10:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/748487#M242000</guid>
      <dc:creator>hendriks</dc:creator>
      <dc:date>2025-06-23T10:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Warning when searching without results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/748515#M242001</link>
      <description>&lt;P&gt;You have a thread from 2020 that states they fixed their problem.&amp;nbsp; I am pretty sure the reason the solution works is similar to what I am going to suggest here.&amp;nbsp; I have found (no scientific evidence to support it) that sometimes the conf files just seem to be buggered and if reset them, it starts to work.&amp;nbsp; I swear the settings are the same before the reset and after, but for some reason it works.&amp;nbsp; Maybe it's voodoo or whatever, but it has worked for me in the past.&lt;BR /&gt;&lt;BR /&gt;Here is a breakdown of quickly resetting the configurations that you need&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The warning suggests the SH is trying to query a non-existent or misconfigured search peer, possibly due to stale or incorrect settings in &lt;/SPAN&gt;&lt;SPAN class=""&gt;outputs.conf&lt;/SPAN&gt;&lt;SPAN class=""&gt; or related configuration files. Resetting &lt;/SPAN&gt;&lt;SPAN class=""&gt;outputs.conf&lt;/SPAN&gt;&lt;SPAN class=""&gt; clears any corrupted or conflicting settings (e.g., incorrect server names, ports, or SSL configurations) that might be preventing the SH from recognizing the IDX as a valid peer. Restarting Splunk ensures a clean state, and re-adding the peer re-establishes the connection with fresh, verified settings.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Steps to Reset and Reconfigure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;OL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Back Up Configuration Files&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Before making changes, back up your Splunk configuration files to avoid losing custom settings.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;On the Search Head, copy the &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;$SPLUNK_HOME\etc\system\local&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; directory (e.g., &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;C:\Program Files\Splunk\etc\system\local&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;) to a safe location (e.g., &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;C:\SplunkBackup&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Delete or Rename &lt;/SPAN&gt;&lt;SPAN class=""&gt;outputs.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Navigate to &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;$SPLUNK_HOME\etc\system\local&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; on the Search Head (e.g., &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;C:\Program Files\Splunk\etc\system\local&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Locate &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;outputs.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;. If it exists, rename it to &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;outputs.conf.bak&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; (or delete it if you’re sure no critical settings are needed).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Note: If &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;outputs.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; is in an app directory (e.g., &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;$SPLUNK_HOME\etc\apps\&amp;lt;app_name&amp;gt;\local&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;), check there too and rename/delete it.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;This ensures Splunk starts with default output settings, clearing any misconfigurations.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Restart Splunk on the Search Head&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Open a Command Prompt as Administrator on the Windows SH host.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Navigate to &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;$SPLUNK_HOME\bin&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; (e.g., &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;cd "C:\Program Files\Splunk\bin"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Run: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;splunk restart&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;This restarts the Splunk service, applying the reset configuration.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Verify Indexer Configuration&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Ensure the Indexer is configured to receive data on the correct port (default: 9997).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;On the Indexer, check &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;$SPLUNK_HOME\etc\system\local\inputs.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; for a &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;[splunktcp://9997]&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; stanza:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;ini&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;splunktcp://9997&lt;/SPAN&gt;&lt;SPAN class=""&gt;]&lt;/SPAN&gt;
&lt;SPAN class=""&gt;disabled&lt;/SPAN&gt; &lt;SPAN class=""&gt;=&lt;/SPAN&gt; &lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;If missing, add it and restart the Indexer (&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;splunk restart&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Confirm port 9997 is open: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;netstat -an | findstr 9997&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; (should show &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;LISTENING&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Reconfigure the Search Peer&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;On the Search Head, log into the Splunk Web UI as an admin.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Go to &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Settings &amp;gt; Distributed Search &amp;gt; Search Peers&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Remove the existing Indexer peer (select the IDX and click &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Remove&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Add the Indexer as a new peer:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Click &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Add New&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Enter the Indexer’s details:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Peer URI&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;https://&amp;lt;Indexer_IP&amp;gt;:8089&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; (e.g., &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;A href="https://192.168.1.100:8089" target="_blank" rel="noopener"&gt;https://192.168.1.100:8089&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Authentication&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: Use the SH admin credentials or a pass4SymmKey (if configured in &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;distsearch.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Replication Settings&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: Ensure settings match your setup (usually default).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Save and wait for the status to show &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Healthy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Alternatively, use the CLI:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;cmd&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;PRE&gt;&lt;SPAN&gt;splunk add search-server https://&amp;lt;Indexer_IP&amp;gt;:8089 -auth &amp;lt;admin&amp;gt;:&amp;lt;password&amp;gt; -remoteUsername &amp;lt;admin&amp;gt; -remotePassword &amp;lt;password&amp;gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Test the Search&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Run your search again from the SH: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;index=_internal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Verify results are returned without the warning.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Check the &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Monitoring Console&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; (&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Settings &amp;gt; Monitoring Console &amp;gt; Search &amp;gt; Distributed Search Health&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;) to confirm the peer is active and responding.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Additional Tips&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Check Network Connectivity&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: Ensure the SH can reach the IDX on port 8089 (management) and 9997 (data). Run: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;telnet &amp;lt;Indexer_IP&amp;gt; 8089&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; and &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;telnet &amp;lt;Indexer_IP&amp;gt; 9997&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; from the SH host. If blocked, check Windows Firewall or network settings.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Verify SSL Settings&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: If using SSL, ensure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;distsearch.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; on the SH and &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;inputs.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; on the IDX align (e.g., &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ssl = true&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;). Check &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;$SPLUNK_HOME\var\log\splunk\splunkd.log&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; on both hosts for SSL errors.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Confirm Splunk Versions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: Your SH and IDX should be on compatible versions (e.g., SH 8.2.2.1 or newer, IDX same or older). Run &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;splunk version&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; on both to confirm. If mismatched, upgrade the SH first.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Debug Logs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: If the issue persists, check &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;$SPLUNK_HOME\var\log\splunk\splunkd.log&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 23 Jun 2025 15:36:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-when-searching-without-results/m-p/748515#M242001</guid>
      <dc:creator>LAME-Creations</dc:creator>
      <dc:date>2025-06-23T15:36:17Z</dc:date>
    </item>
  </channel>
</rss>

