Monitoring Splunk

new indexer not showing in Monitoring console

nawazns5038
Builder

I have added a new indexer to the indexer cluster and I can see it in the Indexer clustering dashboard but I can't see in the monitoring console overview page.

Should anything be done in order to make the new indexer appear in the monitoring console.

0 Karma
1 Solution

nawazns5038
Builder

Go to Settings and then General Setup in monitoring Console and click on Apply Changes

It will change the state of the indexer from "new" to "configured"

View solution in original post

nawazns5038
Builder

Go to Settings and then General Setup in monitoring Console and click on Apply Changes

It will change the state of the indexer from "new" to "configured"

mayurr98
Super Champion

If the Indexer Clustering dashboard on the cluster master is correct, then try this: simply go to the Settings tab in the Monitoring Console and choose General Setup. (Not the overall Settings menu.)
Take a look at the servers listed. If everything looks reasonable, just click Save. You might also do something similar for Forwarder Setup within the MC.

This may clear older entries from the monitoring tables.

nawazns5038
Builder

Yes I see the new indexer added to the instances list ..But it says the state is new

All others as configured

How can I change the settings so that It appears as configured just like others.

0 Karma

493669
Super Champion

Hi @nawazns5038
Set cluster label on master node if not already done . The label is useful for identifying the cluster in the monitoring console.
in $SPLUNK_HOME/etc/system/local/server.conf of master's node in [clustering] stanza add below line:

[clustering] 
cluster_label = cluster1

refer http://docs.splunk.com/Documentation/Splunk/7.0.1/DMC/Setclusterlabels
http://docs.splunk.com/Documentation/Splunk/7.0.1/Indexer/Configuremasterwithserverconf

0 Karma

nawazns5038
Builder

Yes, It is set and the cluster was attached before and all the indexers could be seen, a new indexer was added to the cluster yesterday and unable to find only that one server in DMC ,

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...