Cisco-AMP / amp4e_splunk_events_input

BSD 2-Clause "Simplified" License
8 stars 12 forks source link

Input Creation GUI does not list proper indexes on HF deployment #71

Closed cdw-brendenmorgenthaler closed 2 years ago

cdw-brendenmorgenthaler commented 2 years ago

With a HF connected to an indexer cluster the Input creation GUI only lists the indexes on the HF and does not query the cluster (though the REST api for example) to get the list of available indexes.

samsonnguyen commented 2 years ago

We've seen this happen when the HF does not have access to list the cluster's available indexes. In some cases, there were licensing issues.

I would look into the heavy forwarder's configurations and ensure that it can correctly contact the indexers and has the correct credentials to query for available indexes