I'm trying to setup a Splunk search head. Here is what I've done thus far.
Installed splunk app.
I've installed a copy of an application I've wrote under /opt/splunk/etc/apps on the search head.
I've run the following command on the indexer: ./splunk enable dist-search -auth admin:changeme and restarted the app.
I've run the following command on the search head splunk add search-server -host 10.10.10.123:8089 -auth admin:Mypassword -remoteUsername admin -remotePassword Mypassword
The search head initiates and the GUI for the app I've written appears. However, when I run commands from the search head to indexer, I get "No results found".
The same application works great on the indexer. What step(s) am I missing? Thanks in advance.
I suspect you have not configured any search peers:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch
I suspect you have not configured any search peers:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch