Splunk Enterprise

Splunk Alert manager

indreshdowjones
Explorer

We have installed the following Splunk alert manager app on our search head. During the installation we created new index on search head to store the fired alert data 

  • https://splunkbase.splunk.com/app/2665/ 
  • https://splunkbase.splunk.com/app/3365/

    We are running all our saved searches/alerts from Search head not from the indexers.

    Can you please tell me do we need to create index(alerts) on indexers as well?

    We started receiving lic warnings on search head.

    Mar 21, 2022, 12:00:00 AM
    (8 hours ago)
    This pool has exceeded its configured poolsize=1 bytes. A CLE warning has been recorded for all membersserver_namexxxauto_generated_pool_enterpriseenterprisecle_pool_over_quota

     

    Licensing warnings will be generated today. See License Manager for details. Learn more.3/21/2022, 8:03:41 AM
    License warning issued within past 24 hours: Mon Mar 21 00:00:00 2022 EDT. Refer to the License Usage Report view on license master '' to find out more.3/21/2022, 8:03:41 AM
    Daily indexing volume limit exceeded. Per the Splunk Enterprise license policy in effect, search is disabled after 45 warnings over a 60-day window. Your Splunk deployment is subject to license enforcement. See License Manager for details.

     

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You can create the index on your indexers the same way you created it on the search head.  However, the best practice is to define all of your indexes in an app and deploy that app to all search heads and indexers so all instances have the same list of indexes.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You can create the index on your indexers the same way you created it on the search head.  However, the best practice is to define all of your indexes in an app and deploy that app to all search heads and indexers so all instances have the same list of indexes.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...