Monitoring Splunk

About DMC in stand-alone splunk.

yutaka1005
Builder

I'm recently checking "health check" of DMC, but the following warning is being issued.


One or more non-indexer instances is not forwarding their events to the indexers. This can isolate some of your data and prevent some Monitoring Console dashboards from working.

But In my server configuration, only one stand-alone Splunk is standing.
And the following roles are being applied to the splunk instance as per the manual in DMC.

· Indexer
· License master
· Search head

Why does such a warning appear in a stand-alone environment?
How can I change the setting to avoid this warning?

0 Karma
1 Solution

mattymo
Splunk Employee
Splunk Employee

Hi yutaka1005!

This warning appears because your search head and license master roles do not have an outputs.conf forwarding it's data to the indexers. In other words a non-indexer role is indexing data.... This is a distributed deployment best practice check, which obviously doesn't apply, as you are not running a distributed deployment...

You can disable this check by navigating to Monitoring Console > Settings > Health Check Items and disabling the "Local indexing on non-indexer instances" health check item.

alt text

alt text

- MattyMo

View solution in original post

mattymo
Splunk Employee
Splunk Employee

Hi yutaka1005!

This warning appears because your search head and license master roles do not have an outputs.conf forwarding it's data to the indexers. In other words a non-indexer role is indexing data.... This is a distributed deployment best practice check, which obviously doesn't apply, as you are not running a distributed deployment...

You can disable this check by navigating to Monitoring Console > Settings > Health Check Items and disabling the "Local indexing on non-indexer instances" health check item.

alt text

alt text

- MattyMo

yutaka1005
Builder

Hi mmodestino!
Thank you for answering!

I understood that this health check is for distributed environment and not necessary in a single environment.

And thank you for carefully telling me how to invalidate.
I disabled this health check at DMC.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...