Security

Creating new role and can't see indexes

sreynolds30
Explorer

So I'm creating a new role on my SH version 6 and on this role it can't see indexes on my indexer. I can only see the internal index on the SH. So I can't tie down this role.

Now i can do searches and data from the indexes on my indexer just find.

any thoughts?

Tags (1)
0 Karma

dshpritz
SplunkTrust
SplunkTrust

You will also need to create the indexes on your SH for the indexes to populate in the GUI.

0 Karma

sreynolds30
Explorer

So I'm trying to find the release notes that this issue has been fixed in 6.0.2 before doing the rpm upgrade. Not having luck does anyone have a link to this being fixed in 6.0.2? thanks.

0 Karma

sreynolds30
Explorer

thanks for the replies. I will upgrade to 6.0.2 we just put 6.0.1 on the other day. 🙂

0 Karma

yannK
Splunk Employee
Splunk Employee

the fact that you do not see the indexes is :
- on old versions (4.*)
- on 6.0. because of a bug in 6.0 and 6.0.1
fixed in 6.0.2, please upgrade

OR define the indexes on the search-head to have the list populated.

somesoni2
Revered Legend

You'll face the same issue if you're adding summary indexing. A local version of indexes (with same as in the Indexer) for these indexes to be available from search head.

0 Karma

lguinn2
Legend

This has not been my experience. If I create a index on the indexers, I can see it on the search head - without defining anything on the search head at all.

Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...