<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dispatch_rest_to_indexers in Security</title>
    <link>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/678945#M17645</link>
    <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;I have a question. What exactly '&lt;SPAN&gt;Dispatch_rest_to_indexers' mean ?&lt;BR /&gt;&lt;BR /&gt;I am getting warning when running rest command and I am on splunk cloud.&lt;BR /&gt;Restricting results of the "rest" operator to the local instance because you do not have the "dispatch_rest_to_indexers" capability.&lt;BR /&gt;&lt;BR /&gt;I see many blogs talking about this message but I did not come across clear explanation on what does this parameter exactly mean ?&amp;nbsp;Dispatch_rest_to_indexers . What does this exactly do ?&lt;BR /&gt;&lt;BR /&gt;Please can anyone throw some light on this .&lt;BR /&gt;&lt;BR /&gt;Thanks in Advance,&lt;BR /&gt;PNV&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Feb 2024 09:57:23 GMT</pubDate>
    <dc:creator>Poojitha</dc:creator>
    <dc:date>2024-02-28T09:57:23Z</dc:date>
    <item>
      <title>Dispatch_rest_to_indexers</title>
      <link>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/678945#M17645</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;I have a question. What exactly '&lt;SPAN&gt;Dispatch_rest_to_indexers' mean ?&lt;BR /&gt;&lt;BR /&gt;I am getting warning when running rest command and I am on splunk cloud.&lt;BR /&gt;Restricting results of the "rest" operator to the local instance because you do not have the "dispatch_rest_to_indexers" capability.&lt;BR /&gt;&lt;BR /&gt;I see many blogs talking about this message but I did not come across clear explanation on what does this parameter exactly mean ?&amp;nbsp;Dispatch_rest_to_indexers . What does this exactly do ?&lt;BR /&gt;&lt;BR /&gt;Please can anyone throw some light on this .&lt;BR /&gt;&lt;BR /&gt;Thanks in Advance,&lt;BR /&gt;PNV&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 09:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/678945#M17645</guid>
      <dc:creator>Poojitha</dc:creator>
      <dc:date>2024-02-28T09:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Dispatch_rest_to_indexers</title>
      <link>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/678948#M17646</link>
      <description>&lt;P&gt;This capability does (almost) exactly what it says - lets you dispatch a REST call (via the | rest command) to the indexers (to configured search peers, to be precise - in some cases (typically a Monitoring Console) you might want to REST against a non-indexer peer). Without it you can only call |rest to your local instance.&lt;/P&gt;&lt;P&gt;As far as I remember, that capability is not available for users in Cloud.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 11:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/678948#M17646</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-02-28T11:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dispatch_rest_to_indexers</title>
      <link>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/679326#M17657</link>
      <description>It’s available on Splunk’s own cloud engineers not for any customers, not even for role sc_admin.</description>
      <pubDate>Fri, 01 Mar 2024 17:53:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/679326#M17657</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-03-01T17:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Dispatch_rest_to_indexers</title>
      <link>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/703964#M18193</link>
      <description>&lt;P&gt;if this is not available for us "sc_users" can the splunk engineer create a visualization into the CMC console? or any alternative ways grabbing the health of your application in the search head? please advise, Thank you.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 00:48:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/703964#M18193</guid>
      <dc:creator>ggfloresca</dc:creator>
      <dc:date>2024-11-09T00:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Dispatch_rest_to_indexers</title>
      <link>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/703993#M18194</link>
      <description>&lt;P&gt;No. CMC is pre-built and a far as I know there's no way to edit it from the user's level. Also, what would you want to "monitor" when you can't dispatch rest to indexers? If you want to just dig through the logs, you don't need CMC for that.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2024 07:22:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/703993#M18194</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-11-09T07:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Dispatch_rest_to_indexers</title>
      <link>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/704360#M18200</link>
      <description>Basically it's possible that they create a report which use |rest to indexer if they also set it run as owner. That way it can execute those rest queries and return correct responses.</description>
      <pubDate>Wed, 13 Nov 2024 23:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Dispatch-rest-to-indexers/m-p/704360#M18200</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-11-13T23:39:29Z</dc:date>
    </item>
  </channel>
</rss>

