Deployment Architecture

Replicated Indexes Not Appearing In Cluster Dashboard

dcparker
Path Finder

Hey,

I have set up a clustered Splunk deployment in a lab environment to test. By default, I see _internal and _audit as my replicated indexes. The main index is not there for some reason. I have also added two new indexes in the indexes.conf in master-apps. I verified that this is being pushed to the slave-apps directory on the peers. I also verified that repFactor was set to auto. Any reason why this wouldn't be working or something I missed?

On the search head, when I search _internal, I get results from all 4 peers, so I know that is working.

Thanks for any help you can provide.

Tags (2)
1 Solution

mahamed_splunk
Splunk Employee
Splunk Employee

Can you make sure that the main index has some data? If the index is empty, then there is nothing to replicate and it won't show up in the dashboard as well.

View solution in original post

mahamed_splunk
Splunk Employee
Splunk Employee

Can you make sure that the main index has some data? If the index is empty, then there is nothing to replicate and it won't show up in the dashboard as well.

dcparker
Path Finder

This was correct. I had a forwarding issue and it was not sending data to the proper index, so it did not appear in the clustering dashboard.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...