Not sure that I've picked the correct location - moderators, please move.
I found that I cannot normally run a search on index=_internal and get results from my search peers. Any setting to enable it? Or should I somehow "externalize" the desired data, say, by copying them into a summary index?
Hi @arkadyz1,
which role are you using to run a search on _internal index?
Is your role enabled to access this index?
You can check at @Settings -- Roles -- Your_role -- Indexes].
If you haven't the grants to see that, ask to an administrator.
ciao.
Giuseppe
Sorry, haven't visited Splunk community for a long time - way too much work in other projects. I tried to run it as an admin, so can definitely access all indexes. I can see results from the local _internal index, just not from the search peers.
Hi @arkadyz1,
could you better describe your architecture?
Ciao.
Giuseppe