<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: distributed search: Application does not exist: search in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/distributed-search-Application-does-not-exist-search/m-p/97905#M3604</link>
    <description>&lt;P&gt;One of the points of a distributed setup is the performance benefit of spreading the workload of searching over several indexers (indexers do a major part of work in searches). &lt;/P&gt;

&lt;P&gt;Also, this will let you use load balancing from the forwarders, which will give a higher resilience, since you can take one indexer down for maintenance, and events will still be forwarded to the other indexer.&lt;/P&gt;

&lt;P&gt;If you really want to have separate indexes on separate servers, and to limit where the searches are sent, I guess you could use the splunk_server=serverB search restriction, since Splunk does not inherently know on which indexer a certain index exists.&lt;/P&gt;

&lt;P&gt;Or... hmm.. perhaps that field (splunk_server) just filters incoming results from all indexers... in that case have a look at &lt;CODE&gt;localop&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Localop"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Localop&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/K &lt;/P&gt;</description>
    <pubDate>Wed, 17 Apr 2013 15:12:19 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2013-04-17T15:12:19Z</dc:date>
    <item>
      <title>distributed search: Application does not exist: search</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/distributed-search-Application-does-not-exist-search/m-p/97904#M3603</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;There are 2 splunk servers( A and B) that have differente data and indexes. I have setup distributed search from A to B and B to A.&lt;/P&gt;

&lt;P&gt;searches done from A to B: everything is working as expected. I search for an index that only exists in B and I get results.&lt;/P&gt;

&lt;P&gt;searches done from B to A: searches for indexes in A fail, and searches for local indexes give out warnings about searches in B failing.&lt;/P&gt;

&lt;P&gt;Looking through the search.log I see messages like &lt;BR /&gt;
ERROR dispatchRunner - RunDispatch::runDispatchThread threw error: Application does not exist: search&lt;/P&gt;

&lt;P&gt;However the application exists in both splunk server. And why is every single search being replicated between both splunk servers. If I am looking for something in an index that is in B while I am connected to B is shouldn't replicate the search to A.&lt;/P&gt;

&lt;P&gt;I think I should be using clustering instead of distributed search as I plan on having different indexes and data on each of the splunk servers.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:59:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/distributed-search-Application-does-not-exist-search/m-p/97904#M3603</guid>
      <dc:creator>krugger</dc:creator>
      <dc:date>2013-04-17T14:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: distributed search: Application does not exist: search</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/distributed-search-Application-does-not-exist-search/m-p/97905#M3604</link>
      <description>&lt;P&gt;One of the points of a distributed setup is the performance benefit of spreading the workload of searching over several indexers (indexers do a major part of work in searches). &lt;/P&gt;

&lt;P&gt;Also, this will let you use load balancing from the forwarders, which will give a higher resilience, since you can take one indexer down for maintenance, and events will still be forwarded to the other indexer.&lt;/P&gt;

&lt;P&gt;If you really want to have separate indexes on separate servers, and to limit where the searches are sent, I guess you could use the splunk_server=serverB search restriction, since Splunk does not inherently know on which indexer a certain index exists.&lt;/P&gt;

&lt;P&gt;Or... hmm.. perhaps that field (splunk_server) just filters incoming results from all indexers... in that case have a look at &lt;CODE&gt;localop&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Localop"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Localop&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/K &lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2013 15:12:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/distributed-search-Application-does-not-exist-search/m-p/97905#M3604</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-04-17T15:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: distributed search: Application does not exist: search</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/distributed-search-Application-does-not-exist-search/m-p/97906#M3605</link>
      <description>&lt;P&gt;I would have to edit all the searches on both server. They are like 300 of them, I will do if there is no other way&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2013 17:01:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/distributed-search-Application-does-not-exist-search/m-p/97906#M3605</guid>
      <dc:creator>krugger</dc:creator>
      <dc:date>2013-04-17T17:01:15Z</dc:date>
    </item>
  </channel>
</rss>

