Splunk Search

Why the error when trying to search?

bosseres
Contributor

Hello, everyone!

I get error "WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer." when I'm trying to make search on Search Head.

I started to got such errors after I changed peers in distributed search settings.

Now, I added my indexers in distributed search, and get this error with search "index=*"

when I'm trying search "index=* splunk_server" it works fine.

Peers are connected.

Help me please.

Tags (2)
0 Karma

Roy_9
Motivator

@bosseres I guess this is due to a bug, may folks faced the similar warning when they tried to run the search index=*

Did you followed the below steps:

On your search head do the following:

Settings->Distributed Management Console
(NOTE: Indexers will have N/A shown)
Setup->Apply Changes->Refresh
(NOTE: No changes were actually made)

Verify fix by clicking "Overview" in Distributed Management Console; Indexers will now show correct indexing rate.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...