Splunk Dev

Configured New Non-Clustered Indexer, events not showing up

markhvesta
Path Finder

We have added a new indexer (not clustered) to the pool of our other 2 indexers. One heavy forwarder was pointed to all 3 and these events show up when searching on the new indexer, but the events for the new indexer do not show up in the search heads, nor do they show up in the other indexers.

Is there a configuration setting that was missed here?

Tags (1)
0 Karma
1 Solution

ivanreis
Builder

When you install a new indexer, you have to run a configuration at search head to make the indexer available to searching. Following the steps below:

  1. Log into Splunk Web on the search head and click Settings at the top of the page.
  2. Click Distributed search in the Distributed Environment area.
  3. Click Search peers.
  4. On the Search peers page, select New.
  5. Specify the search peer, along with any authentication settings.

Note: You must precede the search peer's host name or IP address with the URI scheme, either "http" or "https".

  1. Click Save.
  2. Repeat for each of the search head's search peers.

For further information, check this document
https://docs.splunk.com/Documentation/Splunk/8.0.0/DistSearch/Configuredistributedsearch

View solution in original post

ivanreis
Builder

When you install a new indexer, you have to run a configuration at search head to make the indexer available to searching. Following the steps below:

  1. Log into Splunk Web on the search head and click Settings at the top of the page.
  2. Click Distributed search in the Distributed Environment area.
  3. Click Search peers.
  4. On the Search peers page, select New.
  5. Specify the search peer, along with any authentication settings.

Note: You must precede the search peer's host name or IP address with the URI scheme, either "http" or "https".

  1. Click Save.
  2. Repeat for each of the search head's search peers.

For further information, check this document
https://docs.splunk.com/Documentation/Splunk/8.0.0/DistSearch/Configuredistributedsearch

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...