Splunk Search

Why the error when trying to search?

bosseres
Contributor

Hello, everyone!

I get error "WARN: Search filters specified using splunk_server/splunk_server_group do not match any search peer." when I'm trying to make search on Search Head.

I started to got such errors after I changed peers in distributed search settings.

Now, I added my indexers in distributed search, and get this error with search "index=*"

when I'm trying search "index=* splunk_server" it works fine.

Peers are connected.

Help me please.

Labels (1)
Tags (2)
0 Karma

Roy_9
Motivator

@bosseres I guess this is due to a bug, may folks faced the similar warning when they tried to run the search index=*

Did you followed the below steps:

On your search head do the following:

Settings->Distributed Management Console
(NOTE: Indexers will have N/A shown)
Setup->Apply Changes->Refresh
(NOTE: No changes were actually made)

Verify fix by clicking "Overview" in Distributed Management Console; Indexers will now show correct indexing rate.

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...