All Apps and Add-ons

Indexer name change affected CIM Search

hartfoml
Motivator

I recently change the name of two of my indexers to match the name on the third. Now the Splunk_SA_CIM searches that were turned on for acceleration are only running on the indexer that was not changed.

I looked for some kind of lookup file or some kind of module that was installed on the one but not the other two but I was unable to ID the difference.

Any help would be appreciated.

0 Karma
1 Solution

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

View solution in original post

0 Karma

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

0 Karma

Jeremiah
Motivator

You are otherwise able to see data from all 3 indexers when you run a search, and new data is showing up on all three? Are these standalone indexers or are they running in a cluster?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...