Splunk Search

Only one indexer runs the search job?

Explorer

My deployment is:
1 Forwarder + 2 Indexers + 1 Search head.
The two indexers contains about 50GB(about 100,000,000 events) indexed data(load balanced). Once I launch a search "sourcetype=xxx" from search head to get all the results, I found only one of my indexers perform the search job while the other indexer keeps still.
It is really confusing....Why?

0 Karma

SplunkTrust
SplunkTrust
0 Karma