Getting Data In

Splunk Management Console - Error [subsearch] Rest Processor ... https://127.0.0.1:8089

rewritex
Contributor

I have an indexing cluster and this error is when I'm working from the Management Console on the Master.
I go to: Indexing -> Indexes and Volumes -> Index Detail: Deployment (this error is throughout the console)
I am thinking I need to modify the URI within the alert and change it from https://127.0.0.1:8089 to my master IP?
Any advice would be appreciated ... Thanks! ~Sean

alt text

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

I'd venture to say that you are working in a distributed environment and have the wrong role configured for your Cluster Master Node.
Go through your configuration for your Management Console and remove the Indexer role from your Cluster Master instance.

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

I'd venture to say that you are working in a distributed environment and have the wrong role configured for your Cluster Master Node.
Go through your configuration for your Management Console and remove the Indexer role from your Cluster Master instance.

rewritex
Contributor

Yea, that seemed to do it ... Thank You.
I can't recall why it was added ...

Management Console (Master) -> Settings (on the green bar not the top black bar) -> General Setup
1) Edit Actions on the Master
2) Edit Server Roles
2) remove indexer role

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...