Monitoring Splunk

About DMC in stand-alone splunk.

yutaka1005
Builder

I'm recently checking "health check" of DMC, but the following warning is being issued.


One or more non-indexer instances is not forwarding their events to the indexers. This can isolate some of your data and prevent some Monitoring Console dashboards from working.

But In my server configuration, only one stand-alone Splunk is standing.
And the following roles are being applied to the splunk instance as per the manual in DMC.

· Indexer
· License master
· Search head

Why does such a warning appear in a stand-alone environment?
How can I change the setting to avoid this warning?

0 Karma
1 Solution

mattymo
Splunk Employee
Splunk Employee

Hi yutaka1005!

This warning appears because your search head and license master roles do not have an outputs.conf forwarding it's data to the indexers. In other words a non-indexer role is indexing data.... This is a distributed deployment best practice check, which obviously doesn't apply, as you are not running a distributed deployment...

You can disable this check by navigating to Monitoring Console > Settings > Health Check Items and disabling the "Local indexing on non-indexer instances" health check item.

alt text

alt text

- MattyMo

View solution in original post

mattymo
Splunk Employee
Splunk Employee

Hi yutaka1005!

This warning appears because your search head and license master roles do not have an outputs.conf forwarding it's data to the indexers. In other words a non-indexer role is indexing data.... This is a distributed deployment best practice check, which obviously doesn't apply, as you are not running a distributed deployment...

You can disable this check by navigating to Monitoring Console > Settings > Health Check Items and disabling the "Local indexing on non-indexer instances" health check item.

alt text

alt text

- MattyMo

yutaka1005
Builder

Hi mmodestino!
Thank you for answering!

I understood that this health check is for distributed environment and not necessary in a single environment.

And thank you for carefully telling me how to invalidate.
I disabled this health check at DMC.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...