Deployment Architecture

I have made an index on the indexer( in /splunk/etc/local/indexes.conf) but I am not able to see it in my search head while searching. Can you tell me why is this happening?

arpit_1210
Explorer

Q1) I am setting up a test environment for splunk. I have made an index on indexer from backend but when I am searching it from the Search head I am not able to see anything. The search returns 0 events.

Q2) I have made an index from UI in the search head, I am not able to see it form the backend neither in search head nor in indexer. Can you please help me by telling the most probable error that I could have made?

Thank you.

Tags (1)
0 Karma

kalianov
Path Finder

Did you check "Indexes searched by default" in Access controls->Roles after you created new index?

0 Karma

arpit_1210
Explorer

Yes, I have checked the indexes through UI in both Search Head and the Indexer. I am not able to see them in the list of indexes in UI, "settings-->indexes".

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...