Deployment Architecture

Indexes are not showing in Search head cluster?

splunkkrishdee
Explorer

Hey Splukers

Its a distributed environment.

we created index in Cluster Master.

We can access the indexes in SH cluster member..

Now I need to create user roles and add specific index to that role //while doing that

the indexes created in CM is not listing 

then I tried  to check in SH .. setting->indexes.. those indexes not listing..

what could be a reason?

Note:
in SH i can see the data if i put index=<index >name..
where i need to start my analysis?

 

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@splunkkrishdee - Short answer, the index you create on the Cluster Master only stays on the Indexers.

PS Recommendation - You need to deploy the same indexes.conf file on the Search Head to make sure you see the indexes listed on all the places of UI. 

(Forward the data from the SH to Indexers as per recommendation - https://docs.splunk.com/Documentation/Splunk/9.0.2/DistSearch/Forwardsearchheaddata )

(Indexes.conf on the SH will just be used to list the indexes on UI page)

 

I hope this helps!!!

SanjayReddy
SplunkTrust
SplunkTrust

Hi @splunkkrishdee 

index that you created it hope you have pushed the those config to indexers(search peers)

and from cluser master you can check all the avalible indexers and indexes from indexer clustring page , you cant see it from searchead indexes section

SanjayReddy_1-1669181804074.png

SanjayReddy_0-1669181776662.png

 

for assigning index to role , you need to do it from search head 

settings--->roles--> selected user role and edit 

SanjayReddy_2-1669181919443.png

 

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...