Hi,
In a distributed mode with 1 search head and 4 indexers, when making a search through the search head, 2 of the for 4 indexers are not showing indexed data except internal logs of other Splunk infrastructure elements. The indexer is reachable, searchable and indexing data of different equipment. Anyone got an idea? (version 6.3.1)
Thanks !
Thanks for your answer ! Problem solved => multi-sites configuration, need to put site=site0 in server.conf on the search head to perform search accross all sites !
Thanks for your answer ! Problem solved => multi-sites configuration, need to put site=site0 in server.conf on the search head to perform search accross all sites !
is there a possibility that your search is actually just searching for data that literally resides on only 2/4 indexers? - that is, do you have load balancing set up?
Even if you do have load balancing setup, there is a possibility with certain types of data the your stream will all go to the same indexer if you haven't set forceTimebasedAutoLB=true
in outputs.conf