Splunk Dev

Configured New Non-Clustered Indexer, events not showing up

markhvesta
Path Finder

We have added a new indexer (not clustered) to the pool of our other 2 indexers. One heavy forwarder was pointed to all 3 and these events show up when searching on the new indexer, but the events for the new indexer do not show up in the search heads, nor do they show up in the other indexers.

Is there a configuration setting that was missed here?

Tags (1)
0 Karma
1 Solution

ivanreis
Builder

When you install a new indexer, you have to run a configuration at search head to make the indexer available to searching. Following the steps below:

  1. Log into Splunk Web on the search head and click Settings at the top of the page.
  2. Click Distributed search in the Distributed Environment area.
  3. Click Search peers.
  4. On the Search peers page, select New.
  5. Specify the search peer, along with any authentication settings.

Note: You must precede the search peer's host name or IP address with the URI scheme, either "http" or "https".

  1. Click Save.
  2. Repeat for each of the search head's search peers.

For further information, check this document
https://docs.splunk.com/Documentation/Splunk/8.0.0/DistSearch/Configuredistributedsearch

View solution in original post

ivanreis
Builder

When you install a new indexer, you have to run a configuration at search head to make the indexer available to searching. Following the steps below:

  1. Log into Splunk Web on the search head and click Settings at the top of the page.
  2. Click Distributed search in the Distributed Environment area.
  3. Click Search peers.
  4. On the Search peers page, select New.
  5. Specify the search peer, along with any authentication settings.

Note: You must precede the search peer's host name or IP address with the URI scheme, either "http" or "https".

  1. Click Save.
  2. Repeat for each of the search head's search peers.

For further information, check this document
https://docs.splunk.com/Documentation/Splunk/8.0.0/DistSearch/Configuredistributedsearch

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...