All Apps and Add-ons

After installing S.o.S - Splunk on Splunk in my indexer clustering environment, it says "index replication is disabled". How do I verify it's enabled?

brent_weaver
Builder

Cluster replication info

Replication factor: 3

Search factor: 1

Cluster initialization state: Index replication not enabled

Cluster indexing state: Index replication not enabled

How do I verify that this is enabled?

indmast:/home/splunk $ splunk show cluster-status
Your session is invalid.  Please login.
Splunk username: admin
Password:

 Replication factor met
 Search factor met
 All data is searchable
 Indexing Ready YES

 cdopeusvmlogr03.cdopcloud.com   0C9C54E1-44FD-49AA-8E53-D50A0F5AEC19    default
         Searchable YES
         Status  Up
         Bucket Count=1458

 cdopeusvmlogr02.cdopcloud.com   74BCA697-F8DA-44E1-A796-D67636EEA85C    default
         Searchable YES
         Status  Up
         Bucket Count=855

 cdopeusvmlogr04.cdopcloud.com   96A8A6E8-1AB7-4C2D-A768-63BA828BD31D    default
         Searchable YES
         Status  Up
         Bucket Count=1512

 cdopeusvmlogr01.cdopcloud.com   C4B6CB24-2CC7-4381-A7BB-0C45CC103E8C    default
         Searchable YES
         Status  Up
         Bucket Count=1560

What am I missing here?

0 Karma

hexx
Splunk Employee
Splunk Employee

Make sure that you are looking at this particular view from the cluster master! It is not expected for these properties (and that view in general) to be accurate if consulted from an S.o.S app installed anywhere but on the cluster master.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...