Splunk Search

Why are reachable and searchable indexers not showing indexed data when searching in a distributed mode?

andrearodrigues
Explorer

Hi,

In a distributed mode with 1 search head and 4 indexers, when making a search through the search head, 2 of the for 4 indexers are not showing indexed data except internal logs of other Splunk infrastructure elements. The indexer is reachable, searchable and indexing data of different equipment. Anyone got an idea? (version 6.3.1)

Thanks !

1 Solution

andrearodrigues
Explorer

Thanks for your answer ! Problem solved => multi-sites configuration, need to put site=site0 in server.conf on the search head to perform search accross all sites !

View solution in original post

0 Karma

andrearodrigues
Explorer

Thanks for your answer ! Problem solved => multi-sites configuration, need to put site=site0 in server.conf on the search head to perform search accross all sites !

0 Karma

aljohnson_splun
Splunk Employee
Splunk Employee

is there a possibility that your search is actually just searching for data that literally resides on only 2/4 indexers? - that is, do you have load balancing set up?

Even if you do have load balancing setup, there is a possibility with certain types of data the your stream will all go to the same indexer if you haven't set forceTimebasedAutoLB=true in outputs.conf

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...