Splunk Search

Is there a setting to have the license usage search look at _internal data of another server?

bworrellZP
Communicator

Noticed today, since the 6.2.4 update, I get daily license usage just fine. When I go to history, it's blank.

Did the search on the graph and noticed that it's pulling the _internal from the indexer server, not the search head (which is my master license server.) If I put splunk_server=Searchheadservername in the search string, I get data fine.

Is there a setting somewhere that would tell it to look at the _internal of another server (like a user setting for search defaults) or a way to modify the license page to account for this?

Anyone else had this before?

Thanks

0 Karma
1 Solution

bworrellZP
Communicator

Issue has resolved itself, sort of, over night. Yesterday's data shows, but that is it. The Output.conf file appears to have been ignored, a reboot of Splunk on all three servers resolved it. So data was on the search head _internal index, not on the Indexers as it should have been. Will watch closer for errors.

View solution in original post

0 Karma

bworrellZP
Communicator

Issue has resolved itself, sort of, over night. Yesterday's data shows, but that is it. The Output.conf file appears to have been ignored, a reboot of Splunk on all three servers resolved it. So data was on the search head _internal index, not on the Indexers as it should have been. Will watch closer for errors.

0 Karma

bworrellZP
Communicator

Small update, I do have the search head / license master set to forward all logs to the indexers.

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...