All Apps and Add-ons

Indexer name change affected CIM Search

hartfoml
Motivator

I recently change the name of two of my indexers to match the name on the third. Now the Splunk_SA_CIM searches that were turned on for acceleration are only running on the indexer that was not changed.

I looked for some kind of lookup file or some kind of module that was installed on the one but not the other two but I was unable to ID the difference.

Any help would be appreciated.

0 Karma
1 Solution

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

View solution in original post

0 Karma

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

0 Karma

Jeremiah
Motivator

You are otherwise able to see data from all 3 indexers when you run a search, and new data is showing up on all three? Are these standalone indexers or are they running in a cluster?

0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...