Getting Data In

Indexer in cluster not receiving logs from devices external to environment

andyk1116
New Member

I was looking into an issue where one indexer in a cluster was not receiving logs from devices external to my environment. When using the logs to troubleshoot I found a field called "name". The value for this field is "cluster_name:indexer_ip:0" or "cluster_name:indexer_ip:1".

What does the 0 and 1 mean in this field value?

I have not been able to find anything in splunk answers or documentation explaining this.

Search where this field is shown:

index=_internal sourcetype=splunkd source=*metrics.log component=Metrics group=tcpout_connections

Thanks for the help!

0 Karma

nareshinsvu
Builder

something to do with your firewalls?

One observation in my environment is that date_hour = 0 for cluster_name:indexer_ip:1 . I don't think if this has something to do with data not reaching indexers.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...