Deployment Architecture

Why can't I see non-internal indexes in Cluster Master Clustering dashboard after distributing 2 new indexes via configuration bundle?

stefano_guidoba
Communicator

As per subject,

when accessing my cluster master -> clustering panel, in Indexes tab I'm only shown _audit and _internal indexes, while for sure I have another one (index=cisco) with data in it but which is not showed.
I distributed 2 new indexes (cisco + esx) via configuration bundle.

1 Solution

dxu_splunk
Splunk Employee
Splunk Employee

two possibilities:

you didn't make the index a replicated index. to do that, you'll need to add "repFactor=auto" in your indexes.conf for both new indexes (and re-push the bundle to the peers)

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Configurethepeerindexes#1._Edit_indexes.co...

or, there isn't any data/buckets that has been sent to those indexes yet, and they wont show up

View solution in original post

dxu_splunk
Splunk Employee
Splunk Employee

two possibilities:

you didn't make the index a replicated index. to do that, you'll need to add "repFactor=auto" in your indexes.conf for both new indexes (and re-push the bundle to the peers)

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Configurethepeerindexes#1._Edit_indexes.co...

or, there isn't any data/buckets that has been sent to those indexes yet, and they wont show up

stefano_guidoba
Communicator

I didn't add repFactor parameter to indexes.
Thank you.

0 Karma

kundanshekhx
Explorer

Faced exactly the same issue. Issue resolved after adding "repFactor = auto" in test though in production everything is working fine without "repFactor = auto".  

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...