All Apps and Add-ons

Indexer name change affected CIM Search

hartfoml
Motivator

I recently change the name of two of my indexers to match the name on the third. Now the Splunk_SA_CIM searches that were turned on for acceleration are only running on the indexer that was not changed.

I looked for some kind of lookup file or some kind of module that was installed on the one but not the other two but I was unable to ID the difference.

Any help would be appreciated.

0 Karma
1 Solution

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

View solution in original post

0 Karma

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

0 Karma

Jeremiah
Motivator

You are otherwise able to see data from all 3 indexers when you run a search, and new data is showing up on all three? Are these standalone indexers or are they running in a cluster?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...