Deployment Architecture

Why is my search head missing in Distributed Management Console (DMC)?

timmy13
Communicator

I'm sure this is going to be something simple. I have a small Splunk POC environment consisting of a cluster master, 3 indexers, and 2 search heads. When pulling up the DMC on the master, I see all 3 indexers, itself (the master), and 1 search head. But the other search head never shows up. I've even erased and reinstalled Spunk on this search head to no avail. It IS reporting to the license server, and I can search my data with it. Just can't see it in DMC.

Thanks

0 Karma

ThomasControlwa
Path Finder

many thanks,

solution is right @ aaraneta
...and you are hosting the DMC on an instance other than the cluster master, you must add the cluster master as a search peer.

Works very well!

0 Karma

ThomasControlwa
Path Finder

it is also very important to apply the changes by MC (button in the top right)

0 Karma

hexx
Splunk Employee
Splunk Employee

Did you manually add that search-head as a search peer on the DMC / Cluster Master instance? This is a required step:

Repeat steps 3 and 4 for each search head, deployment server, license master, and nonclustered indexer. Do not add clustered indexers, but you must add clustered search heads.

timmy13
Communicator

Yes, I have added it as a search peer and it shows in the list as healthy. yet, does not show up in DMC.

0 Karma

hexx
Splunk Employee
Splunk Employee

That's unexpected. I'm not sure what to suggest besides attempting a factory reset of the DMC, which can be done via a dedicated button in the DMC general setup page.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...