Deployment Architecture

New index not showing in admin console

Sageth
New Member

I created a bunch of new, custom indexes (i.e. index=myApp) that go to a new path and restarted the indexers. The paths were created without any problem and all seems to be well.

I then added index=myApp on the forwarders and recycled splunkd and splunkweb services, but it still seems to be going to main instead of my new index.

A few things that I've noticed:

  • In admin, I don't see the new index to assign to the "Indexes searched by default"
  • In Settings -> Data -> Indexes, I don't see the new index there either. I could try to create it, but I don't want to cause other problems along the way.

Any thoughts?

Tags (1)
0 Karma
1 Solution

somesoni2
SplunkTrust
SplunkTrust

All indexes have to be created on Indexer. If you want to access the Indexes created on Indexer from Forwarder (or Search Head) UI, then you would have to create indexes with similar name on Forwarder(or Search Head). These indexes on Forwarders will not store data but they are required to be created to appear in dropdown on management views.

View solution in original post

somesoni2
SplunkTrust
SplunkTrust

All indexes have to be created on Indexer. If you want to access the Indexes created on Indexer from Forwarder (or Search Head) UI, then you would have to create indexes with similar name on Forwarder(or Search Head). These indexes on Forwarders will not store data but they are required to be created to appear in dropdown on management views.

stath002
Path Finder

So just add your indexes.conf that goes on the indexers to the SH you are saying? Or does it have to be done via the UI?

0 Karma

sloshburch
Splunk Employee
Splunk Employee

UI just edits the conf files. You might want to explore a way to have the same indexes.conf that is deployed to the indexers sent to the SHs so you keep a consistent list. Not required, but a good thing to consider.

0 Karma

stath002
Path Finder

OK cool thats what I thought I just wanted to double check 🙂

0 Karma

Sageth
New Member

Thanks, not having the path on the search head was the part I was missing. Didn't realize it had to be there, even if it wasn't used.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...