All Apps and Add-ons

Indexer name change affected CIM Search

hartfoml
Motivator

I recently change the name of two of my indexers to match the name on the third. Now the Splunk_SA_CIM searches that were turned on for acceleration are only running on the indexer that was not changed.

I looked for some kind of lookup file or some kind of module that was installed on the one but not the other two but I was unable to ID the difference.

Any help would be appreciated.

0 Karma
1 Solution

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

View solution in original post

0 Karma

hartfoml
Motivator

I found the answer the output.conf on the searchhead that had the acceleration running was set to the old server names rather than the IP's As soon as I set the output.conf to the IP's ranter than the Server names the acceleration started to run on all three indexers. Somehow output can affect acceleration.

0 Karma

Jeremiah
Motivator

You are otherwise able to see data from all 3 indexers when you run a search, and new data is showing up on all three? Are these standalone indexers or are they running in a cluster?

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...