Deployment Architecture

Why can't I see non-internal indexes in Cluster Master Clustering dashboard after distributing 2 new indexes via configuration bundle?

stefano_guidoba
Communicator

As per subject,

when accessing my cluster master -> clustering panel, in Indexes tab I'm only shown _audit and _internal indexes, while for sure I have another one (index=cisco) with data in it but which is not showed.
I distributed 2 new indexes (cisco + esx) via configuration bundle.

1 Solution

dxu_splunk
Splunk Employee
Splunk Employee

two possibilities:

you didn't make the index a replicated index. to do that, you'll need to add "repFactor=auto" in your indexes.conf for both new indexes (and re-push the bundle to the peers)

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Configurethepeerindexes#1._Edit_indexes.co...

or, there isn't any data/buckets that has been sent to those indexes yet, and they wont show up

View solution in original post

dxu_splunk
Splunk Employee
Splunk Employee

two possibilities:

you didn't make the index a replicated index. to do that, you'll need to add "repFactor=auto" in your indexes.conf for both new indexes (and re-push the bundle to the peers)

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Configurethepeerindexes#1._Edit_indexes.co...

or, there isn't any data/buckets that has been sent to those indexes yet, and they wont show up

stefano_guidoba
Communicator

I didn't add repFactor parameter to indexes.
Thank you.

0 Karma

kundanshekhx
Explorer

Faced exactly the same issue. Issue resolved after adding "repFactor = auto" in test though in production everything is working fine without "repFactor = auto".  

Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...