Hi Iguinn, thanks for your effort, when I ran the btool check on the indexer instance, I have got the below output but not sure whether this is related to the issue. Kindly guide me if it related to this issue.
Note: The Admin-all_indexers app contains all the index config details
Invalid stanza [_blocksignature] in /opt/splunk/etc/apps/ADMIN-all_indexers/local/indexes.conf, line 197. The block-signing feature is no longer available in Splunk. Please remove stanza=[_blocksignature] from the indexes.conf. For further details, please refer to the related topic in the latest version of 'Securing Splunk' manual on docs.splunk.com.
Invalid key in stanza [search] in /opt/splunk/etc/system/local/limits.conf, line 166: max_results_raw_size (value: 100000000).
Invalid key in stanza [LDAP] in /opt/splunk/etc/apps/ADMIN-all_indexers/default/authentication.conf, line 6: charses (value: utf8).
Invalid key in stanza [search] in /opt/splunk/etc/system/local/limits.conf, line 243: multi_threaded_setup (value: false).
Invalid key in stanza [scheduler] in /opt/splunk/etc/system/local/limits.conf, line 409: peristance_period (value: 30).
Invalid key in stanza [tscollect] in /opt/splunk/etc/system/local/limits.conf, line 467: tsidx_init_file_goal_mb (value: 500).
... View more