<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178200#M51257</link>
    <description>&lt;P&gt;I can't reproduce at will but when the cluster get's in this "odd" state; I happened onto this work around.  Has reoccured a few times on our cluster.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Feb 2015 19:34:57 GMT</pubDate>
    <dc:creator>ii_splunk</dc:creator>
    <dc:date>2015-02-17T19:34:57Z</dc:date>
    <item>
      <title>Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178194#M51251</link>
      <description>&lt;P&gt;WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Possibilities :&lt;/STRONG&gt;&lt;BR /&gt;
relax the primary search criteria -&amp;gt; (index=* doesnt work)&lt;BR /&gt;
widen the time range of the search -&amp;gt;(time range chosen in 'all time')&lt;BR /&gt;
check that the default search indexes for your account include the desired indexes -&amp;gt; (admin role -&amp;gt; using default settings)&lt;/P&gt;

&lt;P&gt;what could be the cause ?&lt;/P&gt;

&lt;P&gt;Splunk version: Splunk 6.0.4 (build 207768)&lt;BR /&gt;
Role : License master servers&lt;BR /&gt;
Slaves version: Splunk 6.2.1 (build 245427)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:36:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178194#M51251</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2020-09-28T18:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178195#M51252</link>
      <description>&lt;P&gt;Hi splunker12er,&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;It is I again &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Does your License master, where you run this search, have any search peers configured? Check in the UI &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;http[s]://YourSplunkHostName:YourSplunkPort/en-GB/manager/search/search/distributed/peers
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or by using this REST command on the license master:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| REST /services/search/distributed/peers
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 08:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178195#M51252</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-01-07T08:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178196#M51253</link>
      <description>&lt;P&gt;try putting splunk_server=* into your base search.&lt;/P&gt;

&lt;P&gt;I just encountered this on a hunk install.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2015 23:19:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178196#M51253</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2015-01-29T23:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178197#M51254</link>
      <description>&lt;P&gt;I think this is a bug that Splunk needs to fix.... here is the work around in case anyone gets this:&lt;/P&gt;

&lt;P&gt;On your search head do the following:&lt;/P&gt;

&lt;P&gt;Settings-&amp;gt;Distributed Management Console&lt;BR /&gt;
(NOTE: Indexers will have N/A shown)&lt;BR /&gt;
Setup-&amp;gt;Apply Changes-&amp;gt;Refresh&lt;BR /&gt;
(NOTE: No changes were actually made)&lt;/P&gt;

&lt;P&gt;Verify fix by clicking "Overview" in Distributed Management Console; Indexers will now show correct indexing rate.&lt;/P&gt;

&lt;P&gt;Search as normal; workaround complete.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 15:53:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178197#M51254</guid>
      <dc:creator>ii_splunk</dc:creator>
      <dc:date>2015-02-17T15:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178198#M51255</link>
      <description>&lt;P&gt;I had the same issue and this fixed it. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 18:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178198#M51255</guid>
      <dc:creator>kylekoza</dc:creator>
      <dc:date>2015-02-17T18:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178199#M51256</link>
      <description>&lt;P&gt;Hi ii_splunk &amp;amp; kylekoza,&lt;/P&gt;

&lt;P&gt;please file a bug report with Splunk Support if this is re-producable &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Troubleshooting/HowtofileagreatSupportcase"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Troubleshooting/HowtofileagreatSupportcase&lt;/A&gt;&lt;BR /&gt;
But to be honest - I believe you had some trouble - this question is not related to Distributed management console. DMC is only available since Splunk 6.2 &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/ReleaseNotes/MeetSplunk#Distributed_management_console"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/ReleaseNotes/MeetSplunk#Distributed_management_console&lt;/A&gt; and @splunker12er is using Splunk 6.0.4&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 19:08:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178199#M51256</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-02-17T19:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178200#M51257</link>
      <description>&lt;P&gt;I can't reproduce at will but when the cluster get's in this "odd" state; I happened onto this work around.  Has reoccured a few times on our cluster.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2015 19:34:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178200#M51257</guid>
      <dc:creator>ii_splunk</dc:creator>
      <dc:date>2015-02-17T19:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178201#M51258</link>
      <description>&lt;P&gt;Here is the known bug SPL-99116&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;After enabling the Distributed Management Console DMC, in "distributed mode", in an indexing cluster, the search-head may not be able to search all the peers. The error will mention splunk_server_group : "Search filters specified using splunk_server/splunk_server_group do not match any search peer". The workarounds are to go to the DMC setup page and hit "apply". To avoid the issue switch the DMC to "single instance" mode.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/ReleaseNotes/KnownIssues#Distributed_search_and_search_head_clustering_issues" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/ReleaseNotes/KnownIssues#Distributed_search_and_search_head_clustering_issues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178201#M51258</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-28T19:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178202#M51259</link>
      <description>&lt;P&gt;ii_splunk,&lt;BR /&gt;
Why and how does that work?  It worked for me, but I don't understand it at all.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Settings-&amp;gt;Distributed Management&lt;BR /&gt;
Console (NOTE: Indexers will have N/A&lt;BR /&gt;
shown) Setup-&amp;gt;Apply Changes-&amp;gt;Refresh&lt;BR /&gt;
(NOTE: No changes were actually made)&lt;/P&gt;

&lt;P&gt;Verify fix by clicking "Overview" in&lt;BR /&gt;
Distributed Management Console;&lt;BR /&gt;
Indexers will now show correct&lt;BR /&gt;
indexing rate.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 28 Jan 2016 13:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178202#M51259</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2016-01-28T13:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178203#M51260</link>
      <description>&lt;P&gt;Of particular note is that this affected all searches.  &lt;/P&gt;

&lt;P&gt;As far as I know no changes where made to our DMC setup; we noticed that all searches quit working on our cluster master with the above mentioned error message.  &lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2016 19:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178203#M51260</guid>
      <dc:creator>triest</dc:creator>
      <dc:date>2016-02-12T19:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178204#M51261</link>
      <description>&lt;P&gt;thank you!  I had the same ridiculous issue haha&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 17:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178204#M51261</guid>
      <dc:creator>ridwanahmed</dc:creator>
      <dc:date>2018-10-24T17:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178205#M51262</link>
      <description>&lt;P&gt;Encountered this same bug on Splunk 8.0.2.1. The steps from  @ii_splunk worked well for me also.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 16:49:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178205#M51262</guid>
      <dc:creator>openpath_llc</dc:creator>
      <dc:date>2020-04-14T16:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178206#M51263</link>
      <description>&lt;P&gt;Same, on 8.0.1.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 07:30:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/178206#M51263</guid>
      <dc:creator>terminaloutcome</dc:creator>
      <dc:date>2020-06-03T07:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/586821#M204384</link>
      <description>&lt;P&gt;Same bug on 8.0.8. The workaround proposed worked!!!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 11:09:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/586821#M204384</guid>
      <dc:creator>marcoscala</dc:creator>
      <dc:date>2022-02-28T11:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run any search query : WARN: Search filters specified using splunk_server/splunk_server_group do not match</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/689596#M234974</link>
      <description>&lt;P&gt;Just ran into this "bug" again in V9.1.1.&amp;nbsp; It is now called the Monitoring Console but otherwise the fix is the same.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 17:55:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-run-any-search-query-WARN-Search-filters-specified/m-p/689596#M234974</guid>
      <dc:creator>mhoustonludlam_</dc:creator>
      <dc:date>2024-06-04T17:55:25Z</dc:date>
    </item>
  </channel>
</rss>

