Getting Data In

Why does the distributed management console show my search head as an indexer?

reswob4
Builder

So I've tried the following suggested configurations:

http://docs.splunk.com/Documentation/Splunk/6.2.0/DistSearch/Forwardsearchheaddata
https://answers.splunk.com/answers/30622/how-to-turn-off-indexing-on-dedicated-search-head.html (doesn't seem to apply to 6.3.3)
https://answers.splunk.com/answers/106166/if-there-is-an-outputs-conf-on-a-dedicated-search-head-doe...

and here is my /opt/splunk/etc/apps/all_forwarder_outputs/local/outputs.conf

BASE SETTINGS

[indexAndForward]
index = false

[tcpout]
defaultGroup = primary_indexers
indexAndForward = false

[tcpout:primary_indexers]
server = indexer1:9997, indexer2:9997

autolb settings

autoLB=true
autoLBFrequency=15
forceTimebasedAutoLB=true

Yet when I look at my Distributed Management Console, it still thinks my search head is also an Indexer.

Is there another outputs.conf I should be configuring?

Thanks

0 Karma
1 Solution

vasildavid
Path Finder

For the DMC app, there is a "General Setup" page under the "Settings" pulldown. Under this page you can set your server roles by editing your servers and assinging whether they are a Search Head, Indexer, License Server, etc.

View solution in original post

vasildavid
Path Finder

For the DMC app, there is a "General Setup" page under the "Settings" pulldown. Under this page you can set your server roles by editing your servers and assinging whether they are a Search Head, Indexer, License Server, etc.

Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...