Deployment Architecture

Single index on indexer not getting new data. Other indexes are.

a238574
Path Finder

I have a splunk cluster with 3 indexers. I have a non replicated index that for some reason has stopped getting new data on one of the indexers. Other indexes on the same node are getting data. What can I look for to figure out why this index on the one node is not getting new data. The data is coming from a pair of Heavy Forwarders which is my 1st target to check but not sure where to look.

Tags (1)
0 Karma
1 Solution

a238574
Path Finder

Found my issue... the indexer in question had been moved to a new IP but the config change had not been updated on the HF

View solution in original post

0 Karma

a238574
Path Finder

Found my issue... the indexer in question had been moved to a new IP but the config change had not been updated on the HF

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

Start with error message in $SPLUNK_HOME/var/log/splunk/splunkd.log on Indexer and Heavy Forwarder. Also check whether receiving port is listening on Indexer.

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Avoid Certificate Expiry Issues in Splunk Enterprise with Certificate Assist

This blog post is part 2 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Using Machine Learning for Hunting Security Threats

REGISTER NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more ...