Installation

Missing Results in Splunk after update from 7 to 8

anae
New Member

Hi, we have a small cluster formed with two indexeres, one search head and one master.
After updating from splunk 7 to splunk 8, the search head will only show results from one of the indexers and not the other.
In the master head everything has green health, it sees both indexers and says they searchable, even though in reality I'm only getting results from one indexer.
Besides this, I've looked in the logs from the search head, the master head and the indexers, but nothing relevant appears.
Does anyone have a hint on what to do to get results from both indexers?

Thanks

0 Karma

DavidHourani
Super Champion

Hi @anae,

Could you please confirm that your search head is part of the cluster and configured as follows in server.conf :
https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Configuresearchheadwithserverconf

It could be that you only have one of the indexers defined as a search peer on the SH which would only allow you to see data from one of the indexers.

Cheers,
David

0 Karma

anae
New Member

it's worth mentioning that if I open up the indexer in question and search directly on it, all the events are there - so it's receiving data and indexing

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...