I have three search heads in a search head cluster and they are all listed in my Distributed Management Console as search heads. Only 2 of the 3 instances are showing data when viewing in the DMC dashboards. The introspection log on the search head not displaying has the data and the
index=_introspection shows data for that search head. I am running Splunk Enterprise 6.3.2.
Why would that one search head not show data in the dashboards?
Can you be more specific about which dashboard is not working, or are all dashboards not working for that search head?
In addition, please double check three things:
1. make sure the search head is a distributed search peer of DMC, so that DMC can query the search head's REST APIs to get current data. If this is set up correctly, at least the dashboards' Snapshot section should show something.
2. make sure the search head is forwarding it's internal logs to the indexers that DMC can query. Since you mentioned "The introspection log on the search head not displaying has the data and the index=_introspection shows data for that search head." I assume you already forwarded the internal logs to the indexers.
3. This might be the actual issue. Go to DMC set up page, and make sure all server roles are correct, then click the Apply Changes button on the top right corner of the set up page. This will make sure that DMC knows about that search head.
I have tried the search activity dashboard and the resource usage dashboard, When I looked at the KV Store dashboard data shows for this instance.