<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic servers-attribute of distsearch.conf not visible in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/servers-attribute-of-distsearch-conf-not-visible/m-p/294695#M5630</link>
    <description>&lt;P&gt;Hello I need a small clarification over distsearch.conf. &lt;/P&gt;

&lt;P&gt;As per the documentation, to connect the SH with Indexer. One can configure in &lt;STRONG&gt;SH&lt;/STRONG&gt; using any of the 3 ways : &lt;STRONG&gt;CLI&lt;/STRONG&gt;, &lt;STRONG&gt;GUI&lt;/STRONG&gt; &amp;amp; &lt;STRONG&gt;Conf&lt;/STRONG&gt; file. The doc nicely describes it, Thanks for that.&lt;/P&gt;

&lt;P&gt;In my case, the splunk env was already setup in my organisation. Now I am not aware which way was followed for adding search peer to search head. &lt;/P&gt;

&lt;P&gt;Now in the &lt;STRONG&gt;SH GUI&lt;/STRONG&gt; the "settings--&amp;gt;Distributed search--&amp;gt;Search peers" server entry is visible, and also the SH fetches the data from Indexer nicely. But my problem is I am not able to find out in which conf file that server settings are stored.&lt;/P&gt;

&lt;P&gt;I tried to locate the distsearch.conf inside whole of splunk dir, but I could not find the server settings in anywhere. Further I tried to debug with &lt;STRONG&gt;btool&lt;/STRONG&gt; cmd in SH and was surprised to see, even in that the servers settings are not visible.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Summarizing the Problem :&lt;/STRONG&gt;  The setting is visible in GUI, but no clue in which conf file that setting is getting stored. &lt;/P&gt;</description>
    <pubDate>Thu, 11 Jan 2018 08:12:57 GMT</pubDate>
    <dc:creator>vicky05ssr</dc:creator>
    <dc:date>2018-01-11T08:12:57Z</dc:date>
    <item>
      <title>servers-attribute of distsearch.conf not visible</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/servers-attribute-of-distsearch-conf-not-visible/m-p/294695#M5630</link>
      <description>&lt;P&gt;Hello I need a small clarification over distsearch.conf. &lt;/P&gt;

&lt;P&gt;As per the documentation, to connect the SH with Indexer. One can configure in &lt;STRONG&gt;SH&lt;/STRONG&gt; using any of the 3 ways : &lt;STRONG&gt;CLI&lt;/STRONG&gt;, &lt;STRONG&gt;GUI&lt;/STRONG&gt; &amp;amp; &lt;STRONG&gt;Conf&lt;/STRONG&gt; file. The doc nicely describes it, Thanks for that.&lt;/P&gt;

&lt;P&gt;In my case, the splunk env was already setup in my organisation. Now I am not aware which way was followed for adding search peer to search head. &lt;/P&gt;

&lt;P&gt;Now in the &lt;STRONG&gt;SH GUI&lt;/STRONG&gt; the "settings--&amp;gt;Distributed search--&amp;gt;Search peers" server entry is visible, and also the SH fetches the data from Indexer nicely. But my problem is I am not able to find out in which conf file that server settings are stored.&lt;/P&gt;

&lt;P&gt;I tried to locate the distsearch.conf inside whole of splunk dir, but I could not find the server settings in anywhere. Further I tried to debug with &lt;STRONG&gt;btool&lt;/STRONG&gt; cmd in SH and was surprised to see, even in that the servers settings are not visible.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Summarizing the Problem :&lt;/STRONG&gt;  The setting is visible in GUI, but no clue in which conf file that setting is getting stored. &lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 08:12:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/servers-attribute-of-distsearch-conf-not-visible/m-p/294695#M5630</guid>
      <dc:creator>vicky05ssr</dc:creator>
      <dc:date>2018-01-11T08:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: servers-attribute of distsearch.conf not visible</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/servers-attribute-of-distsearch-conf-not-visible/m-p/294696#M5631</link>
      <description>&lt;P&gt;&lt;CODE&gt;splunk btool distsearch list --debug&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 15:24:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/servers-attribute-of-distsearch-conf-not-visible/m-p/294696#M5631</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-11T15:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: servers-attribute of distsearch.conf not visible</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/servers-attribute-of-distsearch-conf-not-visible/m-p/294697#M5632</link>
      <description>&lt;P&gt;Thanks for your reply. I did try that, but no entries for servers in the output of above cmd. I have put the output of the above cmd below and also the settings from the GUI. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;The GUI shows the settings, but the conf file doesn't have it stored anywhere.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;GUI proof:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/225707-tst.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;CMD output :&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;`[splunk@test_serverSH bin]$ ./splunk btool distsearch list --debug&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf [bundleEnforcerBlacklist]&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf [bundleEnforcerWhitelist]&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf [distributedSearch]&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf authTokenConnectionTimeout = 5&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf authTokenReceiveTimeout = 10&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf authTokenSendTimeout = 10&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf bestEffortSearch = false&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf connectionTimeout = 10&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf disabled = false&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf peerResolutionThreads = 0&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf receiveTimeout = 600&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf sendTimeout = 30&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf serverTimeout = 10&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf servers =&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf shareBundles = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf statusTimeout = 10&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf useSHPBundleReplication = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf [replicationBlacklist]&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf conf = (system|(apps/&lt;EM&gt;))/(default|local)/server.conf&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf framework = apps/framework/...&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf sampleapp = apps/sample_app/...&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf user_specific_meta = users(/_reserved)?/&lt;/EM&gt;/&lt;EM&gt;/metadata/local.meta&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf [replicationSettings]&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf allowDeltaUpload = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf allowSkipEncoding = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf allowStreamUpload = auto&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf concerningReplicatedFileSize = 50&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf connectionTimeout = 60&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf maxBundleSize = 1024&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf maxMemoryBundleSize = 10&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicationThreads = 5&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf sanitizeMetaFiles = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf sendRcvTimeout = 60&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf [replicationSettings:refineConf]&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.app = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.authorize = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.collections = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.commands = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.eventtypes = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.fields = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.literals = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.multikv = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.props = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.segmenters = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.tags = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.transactiontypes = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf replicate.transforms = true&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf [replicationWhitelist]&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf other = (system|(apps/(?!pdfserver)&lt;/EM&gt;)|users(/_reserved)?/&lt;EM&gt;/&lt;/EM&gt;)/(bin|lookups)/...&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf refine.conf = (system|(apps/&lt;EM&gt;)|users(/_reserved)?/&lt;/EM&gt;/&lt;EM&gt;)/(default|local)/&lt;/EM&gt;.conf&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf refine.metadata = (system|(apps/&lt;EM&gt;)|users(/_reserved)?/&lt;/EM&gt;/&lt;EM&gt;)/metadata/&lt;/EM&gt;.meta&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf searchscripts = searchscripts/...&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf [tokenExchKeys]&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf certDir = $SPLUNK_HOME/etc/auth/distServerKeys&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf genKeyScript = $SPLUNK_HOME/bin/splunk, createssl, audit-keys&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf privateKey = private.pem&lt;BR /&gt;
/opt/splunk/etc/system/default/distsearch.conf publicKey = trusted.pem&lt;/P&gt;

&lt;P&gt;[splunk@test_serverSH bin]$ `&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/servers-attribute-of-distsearch-conf-not-visible/m-p/294697#M5632</guid>
      <dc:creator>vicky05ssr</dc:creator>
      <dc:date>2020-09-29T17:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: servers-attribute of distsearch.conf not visible</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/servers-attribute-of-distsearch-conf-not-visible/m-p/742557#M10388</link>
      <description>&lt;P&gt;I am experiencing the exact same problem.&lt;BR /&gt;&lt;BR /&gt;Version: 9.2.4 Build: c103a21bb11d&lt;/P&gt;</description>
      <pubDate>Mon, 24 Mar 2025 18:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/servers-attribute-of-distsearch-conf-not-visible/m-p/742557#M10388</guid>
      <dc:creator>patrick_castro</dc:creator>
      <dc:date>2025-03-24T18:01:47Z</dc:date>
    </item>
  </channel>
</rss>

