All Apps and Add-ons

Splunk App for Windows only seeing info from main index

hartfoml
Motivator

I have my windows hosts separated in different indexes by organization units. One index for West cost one for east cost one for main office. All the main office stuff is in the main index and I can see them in the Windows APP. I cant see the stuff in the WC index or the EC index. How do I get the windows app to look in the other indexes for windows data?

bmacias84
Champion

I am probably stating the obvious, but have you setup your Indexers to be Search Peers? If not you can do this from the Splunk> Manager >> Distributed Search>> Search Peers.

Here is the complete doc. http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

Note: Distributed Search is only available through the Enterprise License, after you trial license has expired this feature is disabled. http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/TypesofSplunklicenses

If you have already done that. Do you have the Windows TA (Technology Add-on) deploy at your WC and EC indexers? Your TC_add-on will contain all the field extractions etc. which will enable indexers to understand the search request from your Search Head.

Hope this helps.

0 Karma

MarioM
Motivator

did you try by adding your indexes :

Manager » Access controls » Roles » admin » Indexes searched by default
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...