We have added a new indexer (not clustered) to the pool of our other 2 indexers. One heavy forwarder was pointed to all 3 and these events show up when searching on the new indexer, but the events for the new indexer do not show up in the search heads, nor do they show up in the other indexers.
Is there a configuration setting that was missed here?
When you install a new indexer, you have to run a configuration at search head to make the indexer available to searching. Following the steps below:
Note: You must precede the search peer's host name or IP address with the URI scheme, either "http" or "https".
For further information, check this document
https://docs.splunk.com/Documentation/Splunk/8.0.0/DistSearch/Configuredistributedsearch
When you install a new indexer, you have to run a configuration at search head to make the indexer available to searching. Following the steps below:
Note: You must precede the search peer's host name or IP address with the URI scheme, either "http" or "https".
For further information, check this document
https://docs.splunk.com/Documentation/Splunk/8.0.0/DistSearch/Configuredistributedsearch