Hi all,
My current setup consists of
1 x Search Head
3 x Indexers
1 x Cluster Master
1 x DS
1 x Test Forwarder
I created a new index via an indexes.conf file in the cluster master master_apps/_cluster/local/ directory
Pushed that bundle to the indexers and saw the new indexes get created
Forwarded an app on the test instance to the new index and saw the folder get populated with data under the Indexers:$SPLUNK_DB/{test_index}
Now when I run a search in my search head for the new index, it doesn't appear. Nor does it appear under the indexes menu.
Searching only for the host or the index does not return anything.
I can search for the default indexes such as "_internal" and then my test instance will show up.
Am I missing a setting somewhere to complete the setup for the search head to search through all indexes?
They are all currently connected to a license master with a valid license
Thanks for any help
Figured it out. Needed to include the index in the search as well when searching for the host. Also figured out that my default index search needed to include the index by default
Thanks folks
Figured it out. Needed to include the index in the search as well when searching for the host. Also figured out that my default index search needed to include the index by default
Thanks folks
@willso777 If your problem is resolved, please accept the answer to help future readers.
Did you activate distributed search? You add search peers, or indexers, to a Splunk Enterprise instance that you designate as a search head. You do this by specifying each search peer manually (settings >> Distributed search >> Search peers).
More info here.
Your new index will only show in the "index menu" if you put the indexes.conf on your SH and you have permission to access the index.
You should be abel too find you index with index=* if you have the permission to access is