I have my windows hosts separated in different indexes by organization units. One index for West cost one for east cost one for main office. All the main office stuff is in the main index and I can see them in the Windows APP. I cant see the stuff in the WC index or the EC index. How do I get the windows app to look in the other indexes for windows data?
I am probably stating the obvious, but have you setup your Indexers to be Search Peers? If not you can do this from the Splunk> Manager >> Distributed Search>> Search Peers.
Here is the complete doc. http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch
Note: Distributed Search is only available through the Enterprise License, after you trial license has expired this feature is disabled. http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/TypesofSplunklicenses
If you have already done that. Do you have the Windows TA (Technology Add-on) deploy at your WC and EC indexers? Your TC_add-on will contain all the field extractions etc. which will enable indexers to understand the search request from your Search Head.
Hope this helps.
did you try by adding your indexes :
Manager » Access controls » Roles » admin » Indexes searched by default