Installation

Changing role of Splunk instances cause problem to my new search head

sabaKhadivi
Path Finder

As I migrate from one search head to new one, I change the state of one of my indexers to be heavy forwarder for new search head, the problem is that I don't receive HF's logs regularly on new search head ,but on my previous search head I receive logs correctly from that indexer, what is the reason and how can I solve it ?

Labels (3)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...