Deployment Architecture

I have made an index on the indexer( in /splunk/etc/local/indexes.conf) but I am not able to see it in my search head while searching. Can you tell me why is this happening?

arpit_1210
Explorer

Q1) I am setting up a test environment for splunk. I have made an index on indexer from backend but when I am searching it from the Search head I am not able to see anything. The search returns 0 events.

Q2) I have made an index from UI in the search head, I am not able to see it form the backend neither in search head nor in indexer. Can you please help me by telling the most probable error that I could have made?

Thank you.

Tags (1)
0 Karma

kalianov
Path Finder

Did you check "Indexes searched by default" in Access controls->Roles after you created new index?

0 Karma

arpit_1210
Explorer

Yes, I have checked the indexes through UI in both Search Head and the Indexer. I am not able to see them in the list of indexes in UI, "settings-->indexes".

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...