Splunk Search

Why the error when trying to search?

bosseres
Contributor

Hello, everyone!

I get error "WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer." when I'm trying to make search on Search Head.

I started to got such errors after I changed peers in distributed search settings.

Now, I added my indexers in distributed search, and get this error with search "index=*"

when I'm trying search "index=* splunk_server" it works fine.

Peers are connected.

Help me please.

Tags (2)
0 Karma

Roy_9
Motivator

@bosseres I guess this is due to a bug, may folks faced the similar warning when they tried to run the search index=*

Did you followed the below steps:

On your search head do the following:

Settings->Distributed Management Console
(NOTE: Indexers will have N/A shown)
Setup->Apply Changes->Refresh
(NOTE: No changes were actually made)

Verify fix by clicking "Overview" in Distributed Management Console; Indexers will now show correct indexing rate.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...