Deployment Architecture

Unable to fetch logs from Index in Search Head

RAVISHANKAR
Loves-to-Learn Lots

Hello,

I have configured an index inside an indexer and when i try to fetch data from that index in search head not getting any data.

when i search that same index in indexer i could get the data from the index but not from search head.

Could you please assist what configuration needs to be checked on my search head and indexer ?

Note - it's not clustered setup.

 

Thanks

 

Labels (4)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RAVISHANKAR ,

did you configured Distributed Search in Settings, configuring the Indexers for searching?

Ciao.

Giuseppe

0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello  -

 

could you please explain a bit more in detail..

 

configured Distributed Search in Settings, configuring the Indexers for searching? - in indexer or in search head ??

Thanks

0 Karma

jawahir007
Communicator

I hope you did the following configuration to connect search head with indexer. If not, then do it as mentioned below, else verify the configuration.

Configure the Indexer as a Search Peer

  • Log in to the Splunk web interface on your search head.
  • Go to Settings > Distributed Search > Search Peers.
  • Click Add New to add a new search peer (indexer).
  • Enter the management port (usually 8089) and the hostname or IP address of the indexer.
  • If required, enter the username and password of the indexer to establish the connection.
  • Click Save to add the indexer as a search peer.

 

------

If you find this solution helpful, please consider accepting it and awarding karma points !!
0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello - yes this is done and it showing as status up and replication was successfull.

Thanks

0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello - do we need to check anything else further ??

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RAVISHANKAR ,

can you access other indexes or not?

Ciao.

Giuseppe

0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello 

 

I have one indexer and inside that i have created one index and i couldn't fetch data of that index from search head but i can fetch it from the indexer.

Thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...