All Apps and Add-ons

Splunk App for Windows only seeing info from main index

hartfoml
Motivator

I have my windows hosts separated in different indexes by organization units. One index for West cost one for east cost one for main office. All the main office stuff is in the main index and I can see them in the Windows APP. I cant see the stuff in the WC index or the EC index. How do I get the windows app to look in the other indexes for windows data?

bmacias84
Champion

I am probably stating the obvious, but have you setup your Indexers to be Search Peers? If not you can do this from the Splunk> Manager >> Distributed Search>> Search Peers.

Here is the complete doc. http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

Note: Distributed Search is only available through the Enterprise License, after you trial license has expired this feature is disabled. http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/TypesofSplunklicenses

If you have already done that. Do you have the Windows TA (Technology Add-on) deploy at your WC and EC indexers? Your TC_add-on will contain all the field extractions etc. which will enable indexers to understand the search request from your Search Head.

Hope this helps.

0 Karma

MarioM
Motivator

did you try by adding your indexes :

Manager » Access controls » Roles » admin » Indexes searched by default
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...