Splunk Enterprise Security

Splunk Enterprise Security: Why are search results based on Data Models different across all search heads in our multisite search head cluster?

support0
Path Finder

Hello,

On a search head cluster of 3 members with Splunk Enterprise Security, search results match exactly with all Search Heads.

But results based on Data Model are different across all Search heads.
Search affinity is disabled with site = site0.

I don't understand why we have this behavior.

Thanks for your help.

Regards

1 Solution

support0
Path Finder

I think have found the issue, i mean the mistake, search use for "incident reviews" dashboard uses macro named "notable" which use index "notable" and local SH datas are not forwarded to indexers at this time.

View solution in original post

0 Karma

support0
Path Finder

I think have found the issue, i mean the mistake, search use for "incident reviews" dashboard uses macro named "notable" which use index "notable" and local SH datas are not forwarded to indexers at this time.

0 Karma

jkat54
SplunkTrust
SplunkTrust

You should provide us with an example of a search using your datamodel that doesnt give the anticipated results and then tell us what results you're expecting but not seeing.

Also, we need to understand your indexer configuration(s). Do you have just one indexer? 20 indexers, 5 in Atlanta 15 in new york?

My first guess is that your limits.conf is different on your indexers/peers.

0 Karma

support0
Path Finder

Hello,

Thanks for your answer, after investigation it's seem that just this view (incident review) is affected, if i compare data model results they match.

Two sites are in the same region, with high speed network, 5 indexers / 2 SH on each site.

I will check limits parameters with btool but files must be similar, because pushed with deployer.

Maybe it's a caching problem, Splunk side or browser side, i will check that too.

Regards,

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...