Deployment Architecture

Metrics index in index cluster not searchable

las
Contributor

Hi.

I have a setup on Splunk 7.2.4 with a search head, that searches both an index-cluster and a standalone indexer.
I have deployed splunk-add-on-for-infrastructure_131 on both the index-cluster and the standalone indexer.
I have deployed splunk-app-for-infrastructure_131 on the search-head.

When I try to use SAI on the search head I only get results from the standalone indexer not from the Cluster.

This is my first experience with metric indexes so I'm not sure if there has to be some special considerations when using a index-cluster. Other data is searchable in this setup, so the connection is in order between the search-head and the indexcluster.

Can anyone please help getting the clustered data available in the search head?

The index is on the indexcluster, and on the Clustermaster I can see it has some data in it (5 bucket 0.03 GB, 2.8M events on one of the indexers).

Kind regards
las

0 Karma
1 Solution

las
Contributor

There was no problems with the searching of the data.
The problem was with the metric-name, where the props somehow didn't set the first part of the name (process....) so SAI didn't pick up, that there was any data in the index.
This is probably some inconsistency with Splunk Add-on for Windows infrastructure.

View solution in original post

0 Karma

las
Contributor

There was no problems with the searching of the data.
The problem was with the metric-name, where the props somehow didn't set the first part of the name (process....) so SAI didn't pick up, that there was any data in the index.
This is probably some inconsistency with Splunk Add-on for Windows infrastructure.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...