Deployment Architecture

Not getting Indexes list in Indexer cluster.

kunalwalmart
Engager

alt text

My cluster master is not listing the indexes that are being shared by the peers, if I run a search

indexes=* | stats count by index

I am getting results but I am not able to see the same in settings -> Data -> Indexes

I have tried it in search head also no luck even there.

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @kunalwalmart,

Indexes which are avilable on Indexers are not visible in settings -> Data -> Indexes on Cluster Master and SH because these indexes are actually not present on CM and SH.

To check indexes which are available on your indexer cluster and those indexes hold some data, those are available on CM in Settings -> Indexer Clusterting.

I hope this helps.

Thanks,
Harshil

View solution in original post

harsmarvania57
Ultra Champion

Hi @kunalwalmart,

Indexes which are avilable on Indexers are not visible in settings -> Data -> Indexes on Cluster Master and SH because these indexes are actually not present on CM and SH.

To check indexes which are available on your indexer cluster and those indexes hold some data, those are available on CM in Settings -> Indexer Clusterting.

I hope this helps.

Thanks,
Harshil

kunalwalmart
Engager

So for any changes in the indexes I need to go and do them in config files ?

0 Karma

harsmarvania57
Ultra Champion

Yes, when you want to change any index config on Indexer which are in Indexer Cluster, you need to change config files in $SPLUNK_HOME/etc/masterapps/<your app>/local/indexes.confon Cluster Master and then you need to push bundle from Cluster Master to Indexer.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...