I was looking into an issue where one indexer in a cluster was not receiving logs from devices external to my environment. When using the logs to troubleshoot I found a field called "name". The value for this field is "cluster_name:indexer_ip:0" or "cluster_name:indexer_ip:1".
What does the 0 and 1 mean in this field value?
I have not been able to find anything in splunk answers or documentation explaining this.
Search where this field is shown:
index=_internal sourcetype=splunkd source=*metrics.log component=Metrics group=tcpout_connections
Thanks for the help!
something to do with your firewalls?
One observation in my environment is that date_hour = 0
for cluster_name:indexer_ip:1 . I don't think if this has something to do with data not reaching indexers.