All Apps and Add-ons

Splunk App for Windows only seeing info from main index

hartfoml
Motivator

I have my windows hosts separated in different indexes by organization units. One index for West cost one for east cost one for main office. All the main office stuff is in the main index and I can see them in the Windows APP. I cant see the stuff in the WC index or the EC index. How do I get the windows app to look in the other indexes for windows data?

bmacias84
Champion

I am probably stating the obvious, but have you setup your Indexers to be Search Peers? If not you can do this from the Splunk> Manager >> Distributed Search>> Search Peers.

Here is the complete doc. http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

Note: Distributed Search is only available through the Enterprise License, after you trial license has expired this feature is disabled. http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/TypesofSplunklicenses

If you have already done that. Do you have the Windows TA (Technology Add-on) deploy at your WC and EC indexers? Your TC_add-on will contain all the field extractions etc. which will enable indexers to understand the search request from your Search Head.

Hope this helps.

0 Karma

MarioM
Motivator

did you try by adding your indexes :

Manager » Access controls » Roles » admin » Indexes searched by default
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...