Deployment Architecture

splunk search head setup

DTERM
Contributor

I'm trying to setup a Splunk search head. Here is what I've done thus far.

Installed splunk app.

I've installed a copy of an application I've wrote under /opt/splunk/etc/apps on the search head.

I've run the following command on the indexer: ./splunk enable dist-search -auth admin:changeme and restarted the app.

I've run the following command on the search head splunk add search-server -host 10.10.10.123:8089 -auth admin:Mypassword -remoteUsername admin -remotePassword Mypassword

The search head initiates and the GUI for the app I've written appears. However, when I run commands from the search head to indexer, I get "No results found".

The same application works great on the indexer. What step(s) am I missing? Thanks in advance.

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

gkanapathy
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...