Splunk Search

Why the error when trying to search?

bosseres
Contributor

Hello, everyone!

I get error "WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer." when I'm trying to make search on Search Head.

I started to got such errors after I changed peers in distributed search settings.

Now, I added my indexers in distributed search, and get this error with search "index=*"

when I'm trying search "index=* splunk_server" it works fine.

Peers are connected.

Help me please.

Tags (2)
0 Karma

Roy_9
Motivator

@bosseres I guess this is due to a bug, may folks faced the similar warning when they tried to run the search index=*

Did you followed the below steps:

On your search head do the following:

Settings->Distributed Management Console
(NOTE: Indexers will have N/A shown)
Setup->Apply Changes->Refresh
(NOTE: No changes were actually made)

Verify fix by clicking "Overview" in Distributed Management Console; Indexers will now show correct indexing rate.

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...