Deployment Architecture

I have made an index on the indexer( in /splunk/etc/local/indexes.conf) but I am not able to see it in my search head while searching. Can you tell me why is this happening?

arpit_1210
Explorer

Q1) I am setting up a test environment for splunk. I have made an index on indexer from backend but when I am searching it from the Search head I am not able to see anything. The search returns 0 events.

Q2) I have made an index from UI in the search head, I am not able to see it form the backend neither in search head nor in indexer. Can you please help me by telling the most probable error that I could have made?

Thank you.

Tags (1)
0 Karma

kalianov
Path Finder

Did you check "Indexes searched by default" in Access controls->Roles after you created new index?

0 Karma

arpit_1210
Explorer

Yes, I have checked the indexes through UI in both Search Head and the Indexer. I am not able to see them in the list of indexes in UI, "settings-->indexes".

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...