Splunk Enterprise

What are the steps to perform as sanity checks after Splunk Indexer restart?

SudhaP54
Engager
 
Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
In distributed environment you should have MC (monitoring console) set up. Then you can use it to see that everything is ok, it also give you a warning when any peer is down or there are any issues (previously defined in MC).
r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust
In distributed environment you should have MC (monitoring console) set up. Then you can use it to see that everything is ok, it also give you a warning when any peer is down or there are any issues (previously defined in MC).
r. Ismo
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

I would run some searches from the search head to make sure indexers are returning results.

Like -> index=* | dedup sourcetype, splunk_server | table sourcetype, splunk_server

Make sure the splunk_server field mentions all the indexers that you have.

Also, run search -> index=_internal -> in all-time real-time and check for the splunk_server field to make sure that all the indexers are ingesting the new data coming to Splunk as expected.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...