Getting Data In

Indexer in cluster not receiving logs from devices external to environment

andyk1116
New Member

I was looking into an issue where one indexer in a cluster was not receiving logs from devices external to my environment. When using the logs to troubleshoot I found a field called "name". The value for this field is "cluster_name:indexer_ip:0" or "cluster_name:indexer_ip:1".

What does the 0 and 1 mean in this field value?

I have not been able to find anything in splunk answers or documentation explaining this.

Search where this field is shown:

index=_internal sourcetype=splunkd source=*metrics.log component=Metrics group=tcpout_connections

Thanks for the help!

0 Karma

nareshinsvu
Builder

something to do with your firewalls?

One observation in my environment is that date_hour = 0 for cluster_name:indexer_ip:1 . I don't think if this has something to do with data not reaching indexers.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...