We've just deployed a new Splunk 5 cluster. The cluster master claims that the netflow, _audit, and _internal indexes have problems. It says they aren't searchable and there aren't any replicated copies. But if I search on "index=netflow OR index=_internal OR index=_audit", I see all the events I would expect to see.
I'm totally new to a clustered config. What's going on here?
Thx.
Craig
Hi Mustafa,
In my splunk v5.0.4 cluster, I have four slave-indexers, I configured 3 replication factor and 2 search factor, but I am also facing this issue.
Thanks,
Clement
Hi Craig,
Do you have enough number of peers to meet your replication and searchable policies? One reason it could say that it isn't searchable is some of the policies may not be met with current number of peers. We are in the process of refining the error messages to clearly distinguish between when the data is searchable (but with reduced number of copies) vs not completely searchable at all.
Hope it helps
Mustafa