Getting Data In

Indexer in cluster not receiving logs from devices external to environment

New Member

I was looking into an issue where one indexer in a cluster was not receiving logs from devices external to my environment. When using the logs to troubleshoot I found a field called "name". The value for this field is "cluster_name:indexer_ip:0" or "cluster_name:indexer_ip:1".

What does the 0 and 1 mean in this field value?

I have not been able to find anything in splunk answers or documentation explaining this.

Search where this field is shown:

index=_internal sourcetype=splunkd source=*metrics.log component=Metrics group=tcpout_connections

Thanks for the help!

0 Karma


something to do with your firewalls?

One observation in my environment is that date_hour = 0 for cluster_name:indexer_ip:1 . I don't think if this has something to do with data not reaching indexers.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...