Splunk Enterprise

Indexer not searchable

camandhuercue
New Member

Hi there guys,

 

We're having some problems whit the SH and the IDX. We have 5 IDX [3 of them not in cluster, the others are] and when we search only shows 3 on them [the ones out of the cluster], but when we search with the splunk_server=* it shows the five of them. We don't know what is going on, we used another SH and when we put the IDX as search peers it works. We have tried everything but we can't find the answer.

 

I really hope you can help us.

 

Thanks a lot.

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...