In searchhead cluster with six machines, only one SH machine is not giving results for a particular app.
Make sure to have "site = <site>" you can compare the server.conf with working SHs.
Make sure the multisite attribute is set in the server.conf files on your search heads.
It's an Enterprise security app, And a particular dashboard "Incident Review" is give error as "Search did not return any events." on one SH.
On other searchhead we are getting results.
What do you get on the GUI for the search. Do you find any error on the screen?
Is the search head able to do any searches but the search in question? Check the job inspector .
What is the app? What is it supposed to be doing? Is it enabled on all SHs? What are the expected results? Have you checked the logs?
@richgalloway @anilchaithu @sylim_splunk
Can you please help