All Apps and Add-ons

Indexer name change affected CIM Search

hartfoml
Motivator

I recently change the name of two of my indexers to match the name on the third. Now the Splunk_SA_CIM searches that were turned on for acceleration are only running on the indexer that was not changed.

I looked for some kind of lookup file or some kind of module that was installed on the one but not the other two but I was unable to ID the difference.

Any help would be appreciated.

0 Karma
1 Solution

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

View solution in original post

0 Karma

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

0 Karma

Jeremiah
Motivator

You are otherwise able to see data from all 3 indexers when you run a search, and new data is showing up on all three? Are these standalone indexers or are they running in a cluster?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...