Knowledge Management

How to create a new index(not peer index node) from distributed environment?

Leo_Yong
Explorer

The environment is working well, since we have already had some indexes created there, and running as expected. I just want to add another new index with new data.

Here is what I did:
1. create a new index(named: newindex) from search head web page. settings-->Indexes--> New Index
2. from heavy forwarder server, ..../etc/apps/search/local/inputs.conf, added:
[monitor://D:\filepath\filename*]
disable=0
host=a_new_hostname
index=newindex
sourcetype=a_old_sourcetype

  1. copy the log files to path: D:\filepath\

  2. restart splunk on heavy forwarder

After these steps, I could not get any data from search query(like using: index=newindex). By the way, I even couldn't find the index from indexer server web page(settings-->indexes).

Did I miss something? Please advise. Thanks.

Tags (1)
0 Karma
1 Solution

damann
Communicator

You have to create a new Index on the machine your forwarders send the data to.

Try to add a new index by using the WebUI from your Indexer(s) or by configuring indexes.conf on all your indexer.

I hope it works for you!

View solution in original post

0 Karma

damann
Communicator

You have to create a new Index on the machine your forwarders send the data to.

Try to add a new index by using the WebUI from your Indexer(s) or by configuring indexes.conf on all your indexer.

I hope it works for you!

0 Karma

Leo_Yong
Explorer

Thanks for your help. it's working now.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...