Been struggling to get Workload Admission Rules working properly. After a bunch of testing and monitoring with the MC Workload Dashboards, I can see that only searches generated from the CM are applying the Admission Rule Filter. All other search heads ignore the filter.
Anyone run into this issue? On 8.1.3 Splunk Enterprise.
More information, please. The question mentions "Cluster Master", "CM", and "MC", but they are two different things. Which are we talking about? Where and how did you define the workload admission rules? Are the search heads clustered?
--- If this reply helps you, an upvote would be appreciated.