Deployment Architecture

Metrics index in index cluster not searchable

las
Contributor

Hi.

I have a setup on Splunk 7.2.4 with a search head, that searches both an index-cluster and a standalone indexer.
I have deployed splunk-add-on-for-infrastructure_131 on both the index-cluster and the standalone indexer.
I have deployed splunk-app-for-infrastructure_131 on the search-head.

When I try to use SAI on the search head I only get results from the standalone indexer not from the Cluster.

This is my first experience with metric indexes so I'm not sure if there has to be some special considerations when using a index-cluster. Other data is searchable in this setup, so the connection is in order between the search-head and the indexcluster.

Can anyone please help getting the clustered data available in the search head?

The index is on the indexcluster, and on the Clustermaster I can see it has some data in it (5 bucket 0.03 GB, 2.8M events on one of the indexers).

Kind regards
las

0 Karma
1 Solution

las
Contributor

There was no problems with the searching of the data.
The problem was with the metric-name, where the props somehow didn't set the first part of the name (process....) so SAI didn't pick up, that there was any data in the index.
This is probably some inconsistency with Splunk Add-on for Windows infrastructure.

View solution in original post

0 Karma

las
Contributor

There was no problems with the searching of the data.
The problem was with the metric-name, where the props somehow didn't set the first part of the name (process....) so SAI didn't pick up, that there was any data in the index.
This is probably some inconsistency with Splunk Add-on for Windows infrastructure.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...