<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which instance should I send REST API to? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581364#M11210</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242247"&gt;@chenyt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the configuration you define on the search head--users, roles, etc.--will be pushed to the indexers in a bundle used during the search. Different search heads can define different authentication and authorization settings.&lt;/P&gt;&lt;P&gt;Splunk security is decentralized. While you can and should define strict authorization settings on your indexers through configuration deployed by your cluster manager, your users should access the environment through the search head.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jan 2022 17:06:45 GMT</pubDate>
    <dc:creator>tscroggins</dc:creator>
    <dc:date>2022-01-17T17:06:45Z</dc:date>
    <item>
      <title>Which instance should I send REST API to?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581350#M11204</link>
      <description>&lt;P&gt;Hi, everyone.&lt;/P&gt;&lt;P&gt;I am new to Splunk. I have an environment with 3 nodes indexer cluster + cm + Search Head. I am wondering which instance I should send my request to when using REST API?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked API reference and API User tutorial, try to figure it out which endpoint for which instance, but no luck. It seems all HTTPS request send to localhost:8089?&lt;/P&gt;&lt;P&gt;Please help. Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 16:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581350#M11204</guid>
      <dc:creator>chenyt</dc:creator>
      <dc:date>2022-01-17T16:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Which instance should I send REST API to?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581352#M11205</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242247"&gt;@chenyt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should send REST API requests to your search head: &lt;A href="https://yourhostname:8089" target="_blank"&gt;https://yourhostname:8089&lt;/A&gt;. In most cases, REST API access to the your indexers should be limited to other Splunk instances. Your search head provides the authentication and authorization configuration necessary to control access to your data.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 16:26:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581352#M11205</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2022-01-17T16:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Which instance should I send REST API to?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581361#M11208</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49493"&gt;@tscroggins&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Does that mean I don't need to bother which endpoint for which instance, just configure the authentication and authorization on Search Head then send all the REST API request to it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 16:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581361#M11208</guid>
      <dc:creator>chenyt</dc:creator>
      <dc:date>2022-01-17T16:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Which instance should I send REST API to?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581363#M11209</link>
      <description>&lt;P&gt;Yes, because SH will do the rest and fetch the results of you query.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 17:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581363#M11209</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-17T17:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Which instance should I send REST API to?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581364#M11210</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242247"&gt;@chenyt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the configuration you define on the search head--users, roles, etc.--will be pushed to the indexers in a bundle used during the search. Different search heads can define different authentication and authorization settings.&lt;/P&gt;&lt;P&gt;Splunk security is decentralized. While you can and should define strict authorization settings on your indexers through configuration deployed by your cluster manager, your users should access the environment through the search head.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 17:06:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581364#M11210</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2022-01-17T17:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Which instance should I send REST API to?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581365#M11211</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49493"&gt;@tscroggins&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228600"&gt;@SinghK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 17:11:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Which-instance-should-I-send-REST-API-to/m-p/581365#M11211</guid>
      <dc:creator>chenyt</dc:creator>
      <dc:date>2022-01-17T17:11:59Z</dc:date>
    </item>
  </channel>
</rss>

