Deployment Architecture

Custom indexes deployed through master-apps not showing in Indexer Clustering: Master Node section

rigoreatigax
Explorer

alt text

As the title already states, It is expected to lists all indexes and not just internal ones.
I have read in other question that the possible solution is to set replication_factor to auto but not quite sure how to do this, any advise?
There is data in custom indexes, the only issue is that I'm not able to see them in this list.

Thanks in advance.

UPDATE

Tried adding repFactor=auto for each index stanza, didn't work.

Do I have to change the indexes.conf file to _cluster folder? Should I expect everything normal if a delete the custom app and migrate to _cluster?

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @rigoreatigax,

Empty indexes do not show up until they get some data. You do not need to do anything special.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

You should use monitoring console (or change cm’s monitoring to distributed mode) to see those indexes on cluster. Other option is login to individual peer and check those there from cmd line or via web GUI.

Ismo

0 Karma

rigoreatigax
Explorer

Hi, thanks for your answer, everything is working correctly, except for that part, what I want is to see Bucket status from Master node for those indexes.

Cheers.

0 Karma

dmadeira_splunk
Splunk Employee
Splunk Employee

I manage to achieve this by copying opt/splunk/etc/master-apps/_cluster/local/indexes.conf to /opt/splunk/etc/system/local/indexes.conf and creating /opt/splunk/var/lib/splunk/test directory locally on the CM. I did restart the CM and also push the bundle

I hope that helps!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...