Knowledge Management

How to create a new index(not peer index node) from distributed environment?

Leo_Yong
Explorer

The environment is working well, since we have already had some indexes created there, and running as expected. I just want to add another new index with new data.

Here is what I did:
1. create a new index(named: newindex) from search head web page. settings-->Indexes--> New Index
2. from heavy forwarder server, ..../etc/apps/search/local/inputs.conf, added:
[monitor://D:\filepath\filename*]
disable=0
host=a_new_hostname
index=newindex
sourcetype=a_old_sourcetype

  1. copy the log files to path: D:\filepath\

  2. restart splunk on heavy forwarder

After these steps, I could not get any data from search query(like using: index=newindex). By the way, I even couldn't find the index from indexer server web page(settings-->indexes).

Did I miss something? Please advise. Thanks.

Tags (1)
0 Karma
1 Solution

damann
Communicator

You have to create a new Index on the machine your forwarders send the data to.

Try to add a new index by using the WebUI from your Indexer(s) or by configuring indexes.conf on all your indexer.

I hope it works for you!

View solution in original post

0 Karma

damann
Communicator

You have to create a new Index on the machine your forwarders send the data to.

Try to add a new index by using the WebUI from your Indexer(s) or by configuring indexes.conf on all your indexer.

I hope it works for you!

0 Karma

Leo_Yong
Explorer

Thanks for your help. it's working now.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...