Getting Data In

Indexer in cluster not receiving logs from devices external to environment

andyk1116
New Member

I was looking into an issue where one indexer in a cluster was not receiving logs from devices external to my environment. When using the logs to troubleshoot I found a field called "name". The value for this field is "cluster_name:indexer_ip:0" or "cluster_name:indexer_ip:1".

What does the 0 and 1 mean in this field value?

I have not been able to find anything in splunk answers or documentation explaining this.

Search where this field is shown:

index=_internal sourcetype=splunkd source=*metrics.log component=Metrics group=tcpout_connections

Thanks for the help!

0 Karma

nareshinsvu
Builder

something to do with your firewalls?

One observation in my environment is that date_hour = 0 for cluster_name:indexer_ip:1 . I don't think if this has something to do with data not reaching indexers.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...