Getting Data In

Why does the distributed management console show my search head as an indexer?

reswob4
Builder

So I've tried the following suggested configurations:

http://docs.splunk.com/Documentation/Splunk/6.2.0/DistSearch/Forwardsearchheaddata
https://answers.splunk.com/answers/30622/how-to-turn-off-indexing-on-dedicated-search-head.html (doesn't seem to apply to 6.3.3)
https://answers.splunk.com/answers/106166/if-there-is-an-outputs-conf-on-a-dedicated-search-head-doe...

and here is my /opt/splunk/etc/apps/all_forwarder_outputs/local/outputs.conf

BASE SETTINGS

[indexAndForward]
index = false

[tcpout]
defaultGroup = primary_indexers
indexAndForward = false

[tcpout:primary_indexers]
server = indexer1:9997, indexer2:9997

autolb settings

autoLB=true
autoLBFrequency=15
forceTimebasedAutoLB=true

Yet when I look at my Distributed Management Console, it still thinks my search head is also an Indexer.

Is there another outputs.conf I should be configuring?

Thanks

0 Karma
1 Solution

vasildavid
Path Finder

For the DMC app, there is a "General Setup" page under the "Settings" pulldown. Under this page you can set your server roles by editing your servers and assinging whether they are a Search Head, Indexer, License Server, etc.

View solution in original post

vasildavid
Path Finder

For the DMC app, there is a "General Setup" page under the "Settings" pulldown. Under this page you can set your server roles by editing your servers and assinging whether they are a Search Head, Indexer, License Server, etc.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...