Deployment Architecture

I have made an index on the indexer( in /splunk/etc/local/indexes.conf) but I am not able to see it in my search head while searching. Can you tell me why is this happening?

arpit_1210
Explorer

Q1) I am setting up a test environment for splunk. I have made an index on indexer from backend but when I am searching it from the Search head I am not able to see anything. The search returns 0 events.

Q2) I have made an index from UI in the search head, I am not able to see it form the backend neither in search head nor in indexer. Can you please help me by telling the most probable error that I could have made?

Thank you.

Tags (1)
0 Karma

kalianov
Path Finder

Did you check "Indexes searched by default" in Access controls->Roles after you created new index?

0 Karma

arpit_1210
Explorer

Yes, I have checked the indexes through UI in both Search Head and the Indexer. I am not able to see them in the list of indexes in UI, "settings-->indexes".

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...