Deployment Architecture

Why can't I see non-internal indexes in Cluster Master Clustering dashboard after distributing 2 new indexes via configuration bundle?

stefano_guidoba
Communicator

As per subject,

when accessing my cluster master -> clustering panel, in Indexes tab I'm only shown _audit and _internal indexes, while for sure I have another one (index=cisco) with data in it but which is not showed.
I distributed 2 new indexes (cisco + esx) via configuration bundle.

1 Solution

dxu_splunk
Splunk Employee
Splunk Employee

two possibilities:

you didn't make the index a replicated index. to do that, you'll need to add "repFactor=auto" in your indexes.conf for both new indexes (and re-push the bundle to the peers)

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Configurethepeerindexes#1._Edit_indexes.co...

or, there isn't any data/buckets that has been sent to those indexes yet, and they wont show up

View solution in original post

dxu_splunk
Splunk Employee
Splunk Employee

two possibilities:

you didn't make the index a replicated index. to do that, you'll need to add "repFactor=auto" in your indexes.conf for both new indexes (and re-push the bundle to the peers)

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Configurethepeerindexes#1._Edit_indexes.co...

or, there isn't any data/buckets that has been sent to those indexes yet, and they wont show up

stefano_guidoba
Communicator

I didn't add repFactor parameter to indexes.
Thank you.

0 Karma

kundanshekhx
Explorer

Faced exactly the same issue. Issue resolved after adding "repFactor = auto" in test though in production everything is working fine without "repFactor = auto".  

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...