Deployment Architecture

Why can't I see non-internal indexes in Cluster Master Clustering dashboard after distributing 2 new indexes via configuration bundle?

stefano_guidoba
Communicator

As per subject,

when accessing my cluster master -> clustering panel, in Indexes tab I'm only shown _audit and _internal indexes, while for sure I have another one (index=cisco) with data in it but which is not showed.
I distributed 2 new indexes (cisco + esx) via configuration bundle.

1 Solution

dxu_splunk
Splunk Employee
Splunk Employee

two possibilities:

you didn't make the index a replicated index. to do that, you'll need to add "repFactor=auto" in your indexes.conf for both new indexes (and re-push the bundle to the peers)

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Configurethepeerindexes#1._Edit_indexes.co...

or, there isn't any data/buckets that has been sent to those indexes yet, and they wont show up

View solution in original post

dxu_splunk
Splunk Employee
Splunk Employee

two possibilities:

you didn't make the index a replicated index. to do that, you'll need to add "repFactor=auto" in your indexes.conf for both new indexes (and re-push the bundle to the peers)

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Configurethepeerindexes#1._Edit_indexes.co...

or, there isn't any data/buckets that has been sent to those indexes yet, and they wont show up

stefano_guidoba
Communicator

I didn't add repFactor parameter to indexes.
Thank you.

0 Karma

kundanshekhx
Explorer

Faced exactly the same issue. Issue resolved after adding "repFactor = auto" in test though in production everything is working fine without "repFactor = auto".  

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...