Deployment Architecture

index problem search

KhalidAlharthi
Explorer

the index is appearing inside the indexer cluster dashboard inside cluster master but when i try to search it using Search Head i can't find any data i look at the splunkd inside one of the indexers it's appears it working fine

 

should i do restart or something or do i need to change anything?

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Is it just one index you're not seeing data from or are there more of them?

Does your role have access to this index?

Did you verify (like tstats count over"all time") that there is any data in the index at all?

Does your SH even search from the indexers (read - is your environment properly configured regarding distributed searching).

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @KhalidAlharthi 

If you able to view the index name incluster manager page.it means it has searchable data

howerver when you try searhcing with same index name, what was time range you are looking for.

try run for longer timeframe. or you need to have the permission to view the index data in Splunk.

can you please confirm is indexname you are searching has present in allowed list for your role?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...