My Splunk indexer isn't indexing data and I get this error message:
No indexers have reported into this pool today
Any help please?
running this CLI command did it although it added the same exact stuff to the server.conf that we had there manually
splunk edit licenser-localslave -master_uri 'https://master:port'
There are dozens of reasons, most of them firewall-related. Search here:
index=_* AND (ERR* OR FAIL* OR CANNOT OR TIMEOUT OR REFUSED OR REJECTED OR BLOCKED)
so five years later and we are getting the same error with no clear answer / solution in sight
Can you post output of next commands:
- splunk list monitor
- splunk list tcp
- splunk list udp
Have you tried running a search against that particular indexer and see if any data comes back?
index=* earliest=-1h splunk_server=YOURINDEXERHERE
If that's empty, you could try restarting your indexer and see if that helps. If not, then I'd say you need to go through the logs and probably post something else here. You could try using apps such as FireBrigade as that might help debug the problem
Also when you say "pool", is that the license pool? If so, can your indexer contact your license master?
The indexer will keep indexing even if you have violated the license. Data won't be searchable but it'll still be there.
Thank you for your answer, i have one splunk instance (search head + indexer).
i found this error message in the licence web page, there is no data indexed 0 Mo since last week.
Hi, did you try to run the search I indicated above and see if that comes back with any results?
Yes, no results
If none of these help, then we'll need you to take a look at the internal logs (index=_internal) and see if you can spot anything there. Feel free to post anything here.
Hello, yes i restarted the indexer and tried to index locally but the licence still 0Mo : the indexer didn't index anything.. i didn't found error messages or important messages that could help in the logs
If we can't find out what's going on with the options above, it might be better for you to raise a support ticket with Splunk and follow their instructions.