Hi Everyone
Problem: On Splunk App for Unix (latest versions of all the components) on a search head I cannot see hosts from indexers peered to the search head. The data is there if I do a search on index=os ( I can see perf data for all the hosts: CPU, PS etc...), but in the dashboard I can only see the hosts indexed locally (local host and a forwarder). What am I doing wrong?
Example:
= splunk-search (local indexer and search-head) peered with splunk-indexer
=== splunk-forwarder X (forwarding to splunk-search)
=== splunk-forwarder Y (forwarding to splunk-search)
=splunk-indexer (local indexer)
=== splunk-forwarder A (forwarding to splunk-indexer)
=== splunk-forwarder B (forwarding to splunk-indexer)
=== splunk-forwarder C (forwarding to splunk-indexer)
If I go to Splunk App for Unix dashboard on splunk-indexer I can see hosts for:
splunk-indexer (local) + splunk-forwarder A, B, C (which is expected)
If I go to Splunk App for Unix dashboard on splunk-search I can only see hosts for:
splunk-search (local) + splunk-forwarder X,Y - NOT splunk-indexer, nor splunk-forwarder A, B and C
But when I do a search on splunk-search index=os I can see data being found for all hosts.
Do I need to setup Splunk App for Unix in a specific way to display data for remote/peered indexes?
... View more