<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to access Metrics Indexes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516539#M145186</link>
    <description>&lt;P&gt;The solution that I found, and as mentioned by others in different scenarios, is that the Metrics Index has to be defined on the searchheads as well as the indexer cluster. This is unlike an event index which does not, necessarily, have to be defined on a searchheads.&lt;/P&gt;&lt;P&gt;Once I added an indexes.conf for that index on the SH, everything worked fine.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2020 15:08:06 GMT</pubDate>
    <dc:creator>mark_wymer</dc:creator>
    <dc:date>2020-08-27T15:08:06Z</dc:date>
    <item>
      <title>Unable to access Metrics Indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516204#M145038</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;I'm using the (excellent) TrackMe app which uses a Metrics Index. The index has been created on a Indexer Cluster and I've verified that it is actually there ( /opt/splunk/bin/splunk list index -datatype metric ). However, when I try and search the index using&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|  mcollect split=t index="trackme_metrics"&lt;/LI-CODE&gt;&lt;P&gt;I get the following: "&lt;SPAN&gt;Error in 'mcollect' command: Must specify a valid metric index"&lt;BR /&gt;&lt;BR /&gt;This is the 1st and only metrics index on our cluster so I cannot verify that other metrics indexes work OK. Also, the only suggested resolution to this seems to be that I should put the metrics index on our searchhead cluster - but that makes no sense to me!&lt;BR /&gt;&lt;BR /&gt;Am I doing something wrong or is there some setting that I need to configure before I can use a metrics index?&lt;BR /&gt;Many thanks, Mark.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 08:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516204#M145038</guid>
      <dc:creator>mark_wymer</dc:creator>
      <dc:date>2020-08-26T08:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access Metrics Indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516432#M145139</link>
      <description>&lt;P&gt;I suspect you may be confused here, you are running | mcollect which collects data into a metrics index.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps you want | mstats or | mcatalog&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are new to metrics then I'd suggest starting in the analytics workspace (Splunk &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; or metrics workspace (Splunk 7.x?) depending on your Splunk version&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 05:19:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516432#M145139</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-08-27T05:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access Metrics Indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516536#M145184</link>
      <description>&lt;P&gt;Hi, thanks for your response. I cut down the actual SPL for brevity but I do understand your point. Being new to Metrics indexes any pointers are always useful.&lt;/P&gt;&lt;P&gt;i have, however, resolved my issue (posted separately).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 15:03:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516536#M145184</guid>
      <dc:creator>mark_wymer</dc:creator>
      <dc:date>2020-08-27T15:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access Metrics Indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516539#M145186</link>
      <description>&lt;P&gt;The solution that I found, and as mentioned by others in different scenarios, is that the Metrics Index has to be defined on the searchheads as well as the indexer cluster. This is unlike an event index which does not, necessarily, have to be defined on a searchheads.&lt;/P&gt;&lt;P&gt;Once I added an indexes.conf for that index on the SH, everything worked fine.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 15:08:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516539#M145186</guid>
      <dc:creator>mark_wymer</dc:creator>
      <dc:date>2020-08-27T15:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access Metrics Indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516610#M145205</link>
      <description>&lt;P&gt;Oh right. Newer versions of trackme include the indexes.conf for this reason&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 22:58:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/516610#M145205</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-08-27T22:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access Metrics Indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/517807#M145625</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/168207"&gt;@mark_wymer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In true every index you declared on the indexers should be declared in the same way in all the search heads accessing these same indexers, this is a configuration good practice for different reasons such as the index name auto completion, or this use case you encountered.&lt;BR /&gt;&lt;BR /&gt;The good deployment config practice we recommend you to use the Professional Services base config apps:&lt;BR /&gt;&lt;BR /&gt;Base Apps:&amp;nbsp;&lt;A href="https://drive.google.com/open?id=107qWrfsv17j5bLxc21ymTagjtHG0AobF" target="_blank" rel="noopener"&gt;https://drive.google.com/open?id=107qWrfsv17j5bLxc21ymTagjtHG0AobF&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Cluster Apps: &lt;A href="https://drive.google.com/open?id=10aVQXjbgQC99b9InTvncrLFWUrXci3gz" target="_blank" rel="noopener"&gt;https://drive.google.com/open?id=10aVQXjbgQC99b9InTvncrLFWUrXci3gz&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;In your deployment, on the search head you want:&lt;BR /&gt;&lt;BR /&gt;- The same volumes defined than you have in your indexer cluster&lt;BR /&gt;- Which allows you to push the exact same copy of indexes.conf you deploy to the indexers&lt;BR /&gt;&lt;BR /&gt;My best advise is to look at what Splunkenizer does:&lt;BR /&gt;&lt;A href="https://github.com/splunkenizer/Splunkenizer" target="_blank" rel="noopener"&gt;https://github.com/splunkenizer/Splunkenizer&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;(you can spawn a virtual env and analyse for instance)&lt;BR /&gt;Splunkenizer generates a 100% perfect good practice compliant Splunk env. (and is in between such a wonderful thing!)&lt;BR /&gt;&lt;BR /&gt;Last but not least, trackme itself includes a default/indexes.conf, since some years this is not something recommended (from the app publication point of view), however this is required for TrackMe because there are various usage of collect and mcollect commands in different reports, which would lead appinspect to fail if the indexes are not part of the app, plus some more serious issues like you had. So technically you should have had the indexes defined in the search head too&lt;BR /&gt;&lt;BR /&gt;Guilhem&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 19:44:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-access-Metrics-Indexes/m-p/517807#M145625</guid>
      <dc:creator>guilmxm</dc:creator>
      <dc:date>2020-09-03T19:44:24Z</dc:date>
    </item>
  </channel>
</rss>

