Problem: On Splunk App for Unix (latest versions of all the components) on a search head I cannot see hosts from indexers peered to the search head. The data is there if I do a search on index=os ( I can see perf data for all the hosts: CPU, PS etc...), but in the dashboard I can only see the hosts indexed locally (local host and a forwarder). What am I doing wrong?
= splunk-search (local indexer and search-head) peered with splunk-indexer
=== splunk-forwarder X (forwarding to splunk-search)
=== splunk-forwarder Y (forwarding to splunk-search)
=splunk-indexer (local indexer)
=== splunk-forwarder A (forwarding to splunk-indexer)
=== splunk-forwarder B (forwarding to splunk-indexer)
=== splunk-forwarder C (forwarding to splunk-indexer)
If I go to Splunk App for Unix dashboard on splunk-indexer I can see hosts for:
If I go to Splunk App for Unix dashboard on splunk-search I can only see hosts for:
But when I do a search on splunk-search index=os I can see data being found for all hosts.
Do I need to setup Splunk App for Unix in a specific way to display data for remote/peered indexes?
I'm having the same problem, with getting data back from universal forwarders. The data is making it to the indexer/deployment server, but it's not showing up in the dashboard.
See this question:
What worked for me was following those instructions to ensure each host was added to a group, which was then added to a category. I'm guessing that because I deployed the app to the universal forwarders/deployment clients after installing the app on the deployment server/index, the categories and groups weren't populated automatically.