Splunk Search

Why the error when trying to search?

bosseres
Contributor

Hello, everyone!

I get error "WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer." when I'm trying to make search on Search Head.

I started to got such errors after I changed peers in distributed search settings.

Now, I added my indexers in distributed search, and get this error with search "index=*"

when I'm trying search "index=* splunk_server" it works fine.

Peers are connected.

Help me please.

Tags (2)
0 Karma

Roy_9
Motivator

@bosseres I guess this is due to a bug, may folks faced the similar warning when they tried to run the search index=*

Did you followed the below steps:

On your search head do the following:

Settings->Distributed Management Console
(NOTE: Indexers will have N/A shown)
Setup->Apply Changes->Refresh
(NOTE: No changes were actually made)

Verify fix by clicking "Overview" in Distributed Management Console; Indexers will now show correct indexing rate.

0 Karma
Get Updates on the Splunk Community!

Machine Learning - Assisted Adaptive Thresholding

Let’s talk thresholding. Have you set up static thresholds? Tired of static thresholds triggering false ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...