Deployment Architecture

I have made an index on the indexer( in /splunk/etc/local/indexes.conf) but I am not able to see it in my search head while searching. Can you tell me why is this happening?

arpit_1210
Explorer

Q1) I am setting up a test environment for splunk. I have made an index on indexer from backend but when I am searching it from the Search head I am not able to see anything. The search returns 0 events.

Q2) I have made an index from UI in the search head, I am not able to see it form the backend neither in search head nor in indexer. Can you please help me by telling the most probable error that I could have made?

Thank you.

Tags (1)
0 Karma

kalianov
Path Finder

Did you check "Indexes searched by default" in Access controls->Roles after you created new index?

0 Karma

arpit_1210
Explorer

Yes, I have checked the indexes through UI in both Search Head and the Indexer. I am not able to see them in the list of indexes in UI, "settings-->indexes".

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...