I have 2 server groups on Splunk (dmc_group_1 & dmc_group_2) and "dmc_group_1" is the default search group.
When inspecting the DM acceleration scheduled searches, I found that they only run in peers of default search group and .tsidx files were just generated in this group's indexers, even though the search query contained "splunk_server=*". I don't know why Splunk cannot understand "splunk_server=*" in this case.
INFO DistributedSearchResultCollectionManager - Default search group:dmc_group_1 INFO SearchTargeter - Peer NEW-IDX-1 is not in default group dmc_group_1. Not connecting INFO DistributedSearchResultCollectionManager - Not connecting to peer 'NEW-IDX-1' because it has been optimized out.
How can the acceleration scheduled searches run in all search peers without adding "dmc_group_2" to the default group.
Thank you