Hi, I am using 2 linux servers to create a splunk indexer cluster and the version is 5.0.3. Besides, I have 2 search heads with the feature of pooling search head meaning the knowledge bundles are shared on NFS.
When viewing the dashboard of the search app from the search head(SH), I can see I have a total of 34 sourcetypes and 77 hosts. The weird thing is I saw the total number of sourcetypes/hosts drops to single digit sporatically or roughtly once an hour, lasts for 2 minutes and then back to the original numbers.
The weird behavior is consistent on both search heads but never happens to the indexers. I suspect this is related to the configuration issue on pooling search head but wondering if any one shed can some light on this.
Thanks in advance!