Deployment Architecture

Trouble with custom indexer

keekkenen
Engager

Hi, all
I created custom indexer with default parameters and for files/folder monitor define it indexer. After added files to folder and in indexes I see updated indexer info
alt text

But data summary is empty and in the search (*) results is empty too

alt text

What's wrong ?

The forwarder also sending data - it I see by changed index parameters, but it not usable.

if I delete indexer and set monitor without custom indexer - all work correctly.

Please, help me with it trouble.

Tags (1)
0 Karma

keekkenen
Engager

I got my mistake - I didn't add new index for using role - role can't access to index data

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...