Monitoring Splunk

About DMC in stand-alone splunk.

yutaka1005
Builder

I'm recently checking "health check" of DMC, but the following warning is being issued.


One or more non-indexer instances is not forwarding their events to the indexers. This can isolate some of your data and prevent some Monitoring Console dashboards from working.

But In my server configuration, only one stand-alone Splunk is standing.
And the following roles are being applied to the splunk instance as per the manual in DMC.

· Indexer
· License master
· Search head

Why does such a warning appear in a stand-alone environment?
How can I change the setting to avoid this warning?

0 Karma
1 Solution

mattymo
Splunk Employee
Splunk Employee

Hi yutaka1005!

This warning appears because your search head and license master roles do not have an outputs.conf forwarding it's data to the indexers. In other words a non-indexer role is indexing data.... This is a distributed deployment best practice check, which obviously doesn't apply, as you are not running a distributed deployment...

You can disable this check by navigating to Monitoring Console > Settings > Health Check Items and disabling the "Local indexing on non-indexer instances" health check item.

alt text

alt text

- MattyMo

View solution in original post

mattymo
Splunk Employee
Splunk Employee

Hi yutaka1005!

This warning appears because your search head and license master roles do not have an outputs.conf forwarding it's data to the indexers. In other words a non-indexer role is indexing data.... This is a distributed deployment best practice check, which obviously doesn't apply, as you are not running a distributed deployment...

You can disable this check by navigating to Monitoring Console > Settings > Health Check Items and disabling the "Local indexing on non-indexer instances" health check item.

alt text

alt text

- MattyMo

yutaka1005
Builder

Hi mmodestino!
Thank you for answering!

I understood that this health check is for distributed environment and not necessary in a single environment.

And thank you for carefully telling me how to invalidate.
I disabled this health check at DMC.

0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...