Deployment Architecture

Why are Security Roles, Indexes not showing up on SHC?

JDukeSplunk
Builder

I have a number of indexes that only exist on the indexers. In the past, I know that I have been able to select them in the role management GUI and now they do not appear. The authorize.conf on the Search Head Cluster has them listed under the roles.

As follows.

[role_user]
srchDiskQuota = 250
srchIndexesAllowed = application;idx_appdev;idx_citrix;idx_fourd;idx_infrastructure;main;network;os;perfmon;server;wind
srchIndexesDefault = application;idx_appdev;main;perfmon;server;windows;wineventlog;winevents
srchMaxTime = 8640000

However I do not see these in the GUI. Any ideas? Do I now have to make a placeholder indexes with these names on the SHC for them to show up? Seems sloppy.

alt text

1 Solution

JDukeSplunk
Builder

Following @teunlaan advice I placed a dumbed-down copy of my indexes.conf on the search head members. This appears to have worked. Limiting sizes, bare minimum to run.

[perfmon]
coldPath = $SPLUNK_DB/perfmon/colddb
homePath = $SPLUNK_DB/perfmon/db
maxTotalDataSizeMB = 1000
thawedPath = $SPLUNK_DB/perfmon/thaweddb

[security]
coldPath = $SPLUNK_DB/security/colddb
homePath = $SPLUNK_DB/security/db
maxTotalDataSizeMB = 1000
thawedPath = $SPLUNK_DB/security/thaweddb

View solution in original post

0 Karma

JDukeSplunk
Builder

Following @teunlaan advice I placed a dumbed-down copy of my indexes.conf on the search head members. This appears to have worked. Limiting sizes, bare minimum to run.

[perfmon]
coldPath = $SPLUNK_DB/perfmon/colddb
homePath = $SPLUNK_DB/perfmon/db
maxTotalDataSizeMB = 1000
thawedPath = $SPLUNK_DB/perfmon/thaweddb

[security]
coldPath = $SPLUNK_DB/security/colddb
homePath = $SPLUNK_DB/security/db
maxTotalDataSizeMB = 1000
thawedPath = $SPLUNK_DB/security/thaweddb
0 Karma

mehuls93
Engager

Did not worked for me.
Facing the same issue.
Did you updated the indexes.conf on all nodes of SH-C

0 Karma

teunlaan
Contributor

" Do I now have to make a placeholder indexes with these names on the SHC for them to show up? "

Correct.
Just place a copy of you indexes.conf from the indexers in your SHC

0 Karma

ddrillic
Ultra Champion

Hi @teunlaan, not sure about that -

-- Just place a copy of you indexes.conf from the indexers in your SHC

Looking at a functioning cluster at one SH and I see -

cd /opt/splunk/etc
$ find . -name indexes.conf
./system/local/indexes.conf
./system/default/indexes.conf
./master-apps/_cluster/default/indexes.conf
./apps/<app name1>/default/indexes.conf
./apps/<app name2>/default/indexes.conf

The real indexes.conf is nowhere to be found.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...