Getting Data In

Indexer not showing up on _internal or _metric search reports

sonicZ
Contributor

I have 10 indexers and run a bunch of daily reports on heavy volume, hosts and search load.
Recently one of the indexers dropped off all results and i only see 9 out of 10 on all my reports.
What could be causing this, possibly not forwarding _internal indexes, how can i resolve getting the indexer to show up on my reports again?

Tags (2)
0 Karma

sowings
Splunk Employee
Splunk Employee

I'd check the state of the distributed search peers. An indexer will consume its own internal logs ($SPLUNK_HOME/var/log/splunk/*) locally, so if it's not showing up there, I'd guess that it can't be reached at all. Forwarding of the _internal logs shouldn't matter in that case.

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...