Monitoring Splunk

About DMC in stand-alone splunk.

yutaka1005
Builder

I'm recently checking "health check" of DMC, but the following warning is being issued.


One or more non-indexer instances is not forwarding their events to the indexers. This can isolate some of your data and prevent some Monitoring Console dashboards from working.

But In my server configuration, only one stand-alone Splunk is standing.
And the following roles are being applied to the splunk instance as per the manual in DMC.

· Indexer
· License master
· Search head

Why does such a warning appear in a stand-alone environment?
How can I change the setting to avoid this warning?

0 Karma
1 Solution

mattymo
Splunk Employee
Splunk Employee

Hi yutaka1005!

This warning appears because your search head and license master roles do not have an outputs.conf forwarding it's data to the indexers. In other words a non-indexer role is indexing data.... This is a distributed deployment best practice check, which obviously doesn't apply, as you are not running a distributed deployment...

You can disable this check by navigating to Monitoring Console > Settings > Health Check Items and disabling the "Local indexing on non-indexer instances" health check item.

alt text

alt text

- MattyMo

View solution in original post

mattymo
Splunk Employee
Splunk Employee

Hi yutaka1005!

This warning appears because your search head and license master roles do not have an outputs.conf forwarding it's data to the indexers. In other words a non-indexer role is indexing data.... This is a distributed deployment best practice check, which obviously doesn't apply, as you are not running a distributed deployment...

You can disable this check by navigating to Monitoring Console > Settings > Health Check Items and disabling the "Local indexing on non-indexer instances" health check item.

alt text

alt text

- MattyMo

yutaka1005
Builder

Hi mmodestino!
Thank you for answering!

I understood that this health check is for distributed environment and not necessary in a single environment.

And thank you for carefully telling me how to invalidate.
I disabled this health check at DMC.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...