Splunk Search

Is there a setting to have the license usage search look at _internal data of another server?

bworrellZP
Communicator

Noticed today, since the 6.2.4 update, I get daily license usage just fine. When I go to history, it's blank.

Did the search on the graph and noticed that it's pulling the _internal from the indexer server, not the search head (which is my master license server.) If I put splunk_server=Searchheadservername in the search string, I get data fine.

Is there a setting somewhere that would tell it to look at the _internal of another server (like a user setting for search defaults) or a way to modify the license page to account for this?

Anyone else had this before?

Thanks

0 Karma
1 Solution

bworrellZP
Communicator

Issue has resolved itself, sort of, over night. Yesterday's data shows, but that is it. The Output.conf file appears to have been ignored, a reboot of Splunk on all three servers resolved it. So data was on the search head _internal index, not on the Indexers as it should have been. Will watch closer for errors.

View solution in original post

0 Karma

bworrellZP
Communicator

Issue has resolved itself, sort of, over night. Yesterday's data shows, but that is it. The Output.conf file appears to have been ignored, a reboot of Splunk on all three servers resolved it. So data was on the search head _internal index, not on the Indexers as it should have been. Will watch closer for errors.

0 Karma

bworrellZP
Communicator

Small update, I do have the search head / license master set to forward all logs to the indexers.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...