<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Distributed Search, Splunk for Active Directory? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Splunk-for-Active-Directory/m-p/99730#M3681</link>
    <description>&lt;P&gt;I'm working on setting up multiple splunk indexers across a few geographical sites.  Each site contains its own domain controller.  Ideally, I'd like to have each indexer receive the data relevant for its site, and setup distributed search from our search head (easy enough).&lt;/P&gt;

&lt;P&gt;What I'm curious about is how this plays with the Splunk App for Active Directory, and further down the line, Splunk App for VMware.  Do I need to have each site independently configured with the apps/TAs/appropriate indexes as fully functional (stand alone) before the distributed search will function properly on our search head? Or can I just create relevant indexes on each indexer, but leave the TA apps + Splunk for AD app unconfigured?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jan 2013 11:55:54 GMT</pubDate>
    <dc:creator>j0sh3rs</dc:creator>
    <dc:date>2013-01-25T11:55:54Z</dc:date>
    <item>
      <title>Distributed Search, Splunk for Active Directory?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Splunk-for-Active-Directory/m-p/99730#M3681</link>
      <description>&lt;P&gt;I'm working on setting up multiple splunk indexers across a few geographical sites.  Each site contains its own domain controller.  Ideally, I'd like to have each indexer receive the data relevant for its site, and setup distributed search from our search head (easy enough).&lt;/P&gt;

&lt;P&gt;What I'm curious about is how this plays with the Splunk App for Active Directory, and further down the line, Splunk App for VMware.  Do I need to have each site independently configured with the apps/TAs/appropriate indexes as fully functional (stand alone) before the distributed search will function properly on our search head? Or can I just create relevant indexes on each indexer, but leave the TA apps + Splunk for AD app unconfigured?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2013 11:55:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Splunk-for-Active-Directory/m-p/99730#M3681</guid>
      <dc:creator>j0sh3rs</dc:creator>
      <dc:date>2013-01-25T11:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Search, Splunk for Active Directory?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Splunk-for-Active-Directory/m-p/99731#M3682</link>
      <description>&lt;P&gt;Does the &lt;A href="http://docs.splunk.com/Documentation/ActiveDirectory/latest/DeployAD/WhataSplunkAppforActiveDirectorydeploymentlookslike"&gt;diagram in the documentation of a distributed deployment&lt;/A&gt; give you the detail you need?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 12:14:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Splunk-for-Active-Directory/m-p/99731#M3682</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2013-01-28T12:14:15Z</dc:date>
    </item>
  </channel>
</rss>

