Deployment Architecture

I am not able to see custom indexes in cluster master

btshivanand
Path Finder

Hello Friends,

I am not able to see custom indexes in splunk cluster master.can you please help me?

 

Regards,Shivanand

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @btshivanand,

only two questions:

  • what do you mean with "custom indexes": not clustered indexes or  indexes cleated by you on the Master Node?
  • what do you mean with "to see"? are you speaking in searches or on Master Node?

If you don't create an index on Master Node you cannot see it on the same MN, but only on indexers.

So check how you created indexes: indexes must be creted in indexes.con on Master Node, putting this conf file in $SPLUNK_HOME/etc/master-apps/_cluster or (better) in a dedicated app (called e.g. TA_Indexers) sited in $SPLUNK_HOME/etc/master-apps.

For more infos see at https://docs.splunk.com/Documentation/Splunk/8.0.5/Indexer/Clusterdeploymentoverview

Ciao.

Giuseppe

0 Karma

btshivanand
Path Finder

Thanks for the reply.

Custom indexes are created by me on indexer master node.

i am speaking in master node.I am not able to see the custom indexes under settings -->indexer clustering---->indexes....

created custom indexes under below path

/opt/splunk/etc/master-apps/ee_all_indexes/local 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @btshivanand,

Did you inserted, in indexes stanzas

repFactor = auto

?

Ciao.

Giuseppe 

0 Karma

btshivanand
Path Finder

i am not using that .So i need to use that stanza for all the custom index.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @btshivanand,

yes you need!

I encountered the same problem in the past.

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

That must be on every index definition on clustered indexers.

r. Ismo

0 Karma

btshivanand
Path Finder

Ok. Thanks .. Let me try

 

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...