Deployment Architecture

Unable to fetch logs from Index in Search Head

RAVISHANKAR
Loves-to-Learn Lots

Hello,

I have configured an index inside an indexer and when i try to fetch data from that index in search head not getting any data.

when i search that same index in indexer i could get the data from the index but not from search head.

Could you please assist what configuration needs to be checked on my search head and indexer ?

Note - it's not clustered setup.

 

Thanks

 

Labels (4)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RAVISHANKAR ,

did you configured Distributed Search in Settings, configuring the Indexers for searching?

Ciao.

Giuseppe

0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello  -

 

could you please explain a bit more in detail..

 

configured Distributed Search in Settings, configuring the Indexers for searching? - in indexer or in search head ??

Thanks

0 Karma

jawahir007
Communicator

I hope you did the following configuration to connect search head with indexer. If not, then do it as mentioned below, else verify the configuration.

Configure the Indexer as a Search Peer

  • Log in to the Splunk web interface on your search head.
  • Go to Settings > Distributed Search > Search Peers.
  • Click Add New to add a new search peer (indexer).
  • Enter the management port (usually 8089) and the hostname or IP address of the indexer.
  • If required, enter the username and password of the indexer to establish the connection.
  • Click Save to add the indexer as a search peer.

 

------

If you find this solution helpful, please consider accepting it and awarding karma points !!
0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello - yes this is done and it showing as status up and replication was successfull.

Thanks

0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello - do we need to check anything else further ??

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @RAVISHANKAR ,

can you access other indexes or not?

Ciao.

Giuseppe

0 Karma

RAVISHANKAR
Loves-to-Learn Lots

@gcusello 

 

I have one indexer and inside that i have created one index and i couldn't fetch data of that index from search head but i can fetch it from the indexer.

Thanks

0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 2)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Index This | What is the next number in the series? 7,645 5,764 4,576…

February 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Buttercup Games: Further Dashboarding Techniques

Hello! We are excited to kick off a new series of blogs from SplunkTrust member ITWhisperer, who demonstrates ...