Deployment Architecture

Unable to fetch logs from Index in Search Head

RAVISHANKAR
Loves-to-Learn Lots

Hello,

I have configured an index inside an indexer and when i try to fetch data from that index in search head not getting any data.

when i search that same index in indexer i could get the data from the index but not from search head.

Could you please assist what configuration needs to be checked on my search head and indexer ?

Note - it's not clustered setup.

 

Thanks

 

Labels (4)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RAVISHANKAR ,

did you configured Distributed Search in Settings, configuring the Indexers for searching?

Ciao.

Giuseppe

0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello  -

 

could you please explain a bit more in detail..

 

configured Distributed Search in Settings, configuring the Indexers for searching? - in indexer or in search head ??

Thanks

0 Karma

jawahir007
Communicator

I hope you did the following configuration to connect search head with indexer. If not, then do it as mentioned below, else verify the configuration.

Configure the Indexer as a Search Peer

  • Log in to the Splunk web interface on your search head.
  • Go to Settings > Distributed Search > Search Peers.
  • Click Add New to add a new search peer (indexer).
  • Enter the management port (usually 8089) and the hostname or IP address of the indexer.
  • If required, enter the username and password of the indexer to establish the connection.
  • Click Save to add the indexer as a search peer.

 

------

If you find this solution helpful, please consider accepting it and awarding karma points !!
0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello - yes this is done and it showing as status up and replication was successfull.

Thanks

0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello - do we need to check anything else further ??

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RAVISHANKAR ,

can you access other indexes or not?

Ciao.

Giuseppe

0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello 

 

I have one indexer and inside that i have created one index and i couldn't fetch data of that index from search head but i can fetch it from the indexer.

Thanks

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...