Getting Data In

Clustered indexes not showing up in the index list.

some_guy
Path Finder

Hello. Splunk 6.2.1. Built a single-site index cluster. Two search heads. I can create test indexes across the cluster by editing indexes.conf on the cluster-master, then deploying a config bundle. Works great.

Problem: My search heads don't see the test indexes in an index list. In splunkweb, Settings->Indexer Clustering, I've configured the master as a searched cluster, and everything is up/searchable/met. Still, my new test indices only show up on the master and the indexers themselves.

Any help appreciated. Thanks.

1 Solution

Steve_G_
Splunk Employee
Splunk Employee

Do you have any data in the indexes? New indexes only show up in the Indexes tab of the Master Dashboard once they have data in them. See the "note" here: http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Howtomonitoracluster#Indexes_tab

View solution in original post

Michael
Contributor

An addendum to this question, what indexes should be visible on the Indexer Clustering dashboard?

I have dozens of active indexes in my cluster (yes, with data and my role does have access), but this management console only shows:
_audit
_internal
_telemetry
main
summary

Should all my indices be reflected here, or am I not understanding what this is supposed to be reflecting? Documentation is not clear on this part...

thanks!
Mike

0 Karma

Steve_G_
Splunk Employee
Splunk Employee

Do you have any data in the indexes? New indexes only show up in the Indexes tab of the Master Dashboard once they have data in them. See the "note" here: http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Howtomonitoracluster#Indexes_tab

some_guy
Path Finder

These indexes are indeed empty. That must be it. Thanks!

(my test indices do show up when editing a role...ie: "Indexes searched by default" )

0 Karma

athorat3
New Member

@Steve G.

I have a similar issue where I do not see all the indexes under "All Index" button under >> Data Rebalance

https://answers.splunk.com/answers/577726/issues-with-data-rebalance-from-clustermaster.html?minQues...

Any inputs?

0 Karma

wahidha_farook
New Member

Similar issue in 8.2.1 - do not see all the indexes under "All Index" button under >> Data Rebalance

 

Is this known issue? seems to be there in later versions as well. Was it even fixed or under fix?

0 Karma

kairobin
Path Finder

Hi, Did you find a fix for this issue?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...