Deployment Architecture

Not getting Indexes list in Indexer cluster.

kunalwalmart
Engager

alt text

My cluster master is not listing the indexes that are being shared by the peers, if I run a search

indexes=* | stats count by index

I am getting results but I am not able to see the same in settings -> Data -> Indexes

I have tried it in search head also no luck even there.

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @kunalwalmart,

Indexes which are avilable on Indexers are not visible in settings -> Data -> Indexes on Cluster Master and SH because these indexes are actually not present on CM and SH.

To check indexes which are available on your indexer cluster and those indexes hold some data, those are available on CM in Settings -> Indexer Clusterting.

I hope this helps.

Thanks,
Harshil

View solution in original post

harsmarvania57
Ultra Champion

Hi @kunalwalmart,

Indexes which are avilable on Indexers are not visible in settings -> Data -> Indexes on Cluster Master and SH because these indexes are actually not present on CM and SH.

To check indexes which are available on your indexer cluster and those indexes hold some data, those are available on CM in Settings -> Indexer Clusterting.

I hope this helps.

Thanks,
Harshil

kunalwalmart
Engager

So for any changes in the indexes I need to go and do them in config files ?

0 Karma

harsmarvania57
Ultra Champion

Yes, when you want to change any index config on Indexer which are in Indexer Cluster, you need to change config files in $SPLUNK_HOME/etc/masterapps/<your app>/local/indexes.confon Cluster Master and then you need to push bundle from Cluster Master to Indexer.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...