Splunk Enterprise

Indexes not visible on searchhead in splunk in non cluster enviornment

smdasim
Explorer

Hi Team,

I have one Search head(deloyment server) ,two indexer and two forwarder in the network .I created web index on both indexer ,
when i try to add data from search head into web index .The web index does not show on the forwader and it is not present on search head ,However i did create web index on both indexer .

Please let me know why my web index on indexer is not visible in search head .

thanks
smdasim

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

That's normal. To add data from the search head specify the index name manually.

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...