All Apps and Add-ons

Splunk App for Windows only seeing info from main index

hartfoml
Motivator

I have my windows hosts separated in different indexes by organization units. One index for West cost one for east cost one for main office. All the main office stuff is in the main index and I can see them in the Windows APP. I cant see the stuff in the WC index or the EC index. How do I get the windows app to look in the other indexes for windows data?

bmacias84
Champion

I am probably stating the obvious, but have you setup your Indexers to be Search Peers? If not you can do this from the Splunk> Manager >> Distributed Search>> Search Peers.

Here is the complete doc. http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

Note: Distributed Search is only available through the Enterprise License, after you trial license has expired this feature is disabled. http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/TypesofSplunklicenses

If you have already done that. Do you have the Windows TA (Technology Add-on) deploy at your WC and EC indexers? Your TC_add-on will contain all the field extractions etc. which will enable indexers to understand the search request from your Search Head.

Hope this helps.

0 Karma

MarioM
Motivator

did you try by adding your indexes :

Manager » Access controls » Roles » admin » Indexes searched by default
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...