<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: one-way distributed searches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/one-way-distributed-searches/m-p/9386#M100</link>
    <description>&lt;P&gt;matt, i think you meant to link this page in the documentation, "Configure distributed search".&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch" rel="nofollow"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jun 2010 23:57:49 GMT</pubDate>
    <dc:creator>sophy</dc:creator>
    <dc:date>2010-06-22T23:57:49Z</dc:date>
    <item>
      <title>one-way distributed searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/one-way-distributed-searches/m-p/9383#M97</link>
      <description>&lt;P&gt;Given servers A and B, how do you search both A AND B from server A, but disallow B from searching against A?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2010 12:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/one-way-distributed-searches/m-p/9383#M97</guid>
      <dc:creator>amrit</dc:creator>
      <dc:date>2010-01-21T12:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: one-way distributed searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/one-way-distributed-searches/m-p/9384#M98</link>
      <description>&lt;P&gt;Remove server A from the peer list in server B's distsearch.conf.  Docs have an example &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Restrictwhatsomeuserscansee" rel="nofollow"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2010 12:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/one-way-distributed-searches/m-p/9384#M98</guid>
      <dc:creator>matt</dc:creator>
      <dc:date>2010-01-21T12:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: one-way distributed searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/one-way-distributed-searches/m-p/9385#M99</link>
      <description>&lt;P&gt;Distributed search is always configured one way at a time, from a search head node to an index node. If you configure A to be allowed to search B, server B will not be able to search A (unless you specifically perform the configuration steps to do so).&lt;/P&gt;

&lt;P&gt;If server B is already able to search server A, then in addition to removing A from server B's distsearch.conf file, you should also remove server B's authorized key from server A's $SPLUNK_HOME/etc/auth/distSearchKeys/ folder. If you do not do so, then an administrator of B (who is not an administrator of A) can regain access to A simply by adding A back to the distsearch.conf file.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2010 13:36:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/one-way-distributed-searches/m-p/9385#M99</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-01-21T13:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: one-way distributed searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/one-way-distributed-searches/m-p/9386#M100</link>
      <description>&lt;P&gt;matt, i think you meant to link this page in the documentation, "Configure distributed search".&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch" rel="nofollow"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuredistributedsearch&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2010 23:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/one-way-distributed-searches/m-p/9386#M100</guid>
      <dc:creator>sophy</dc:creator>
      <dc:date>2010-06-22T23:57:49Z</dc:date>
    </item>
  </channel>
</rss>

