We've just deployed a new Splunk 5 cluster. The cluster master claims that the netflow, _audit, and _internal indexes have problems. It says they aren't searchable and there aren't any replicated copies. But if I search on "index=netflow OR index=_internal OR index=_audit", I see all the events I would expect to see.
I'm totally new to a clustered config. What's going on here?
Thx.
Craig