<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: distributed search both ways? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12978#M1110</link>
    <description>&lt;P&gt;Perfect!  this worked out great!  Thank you very much!&lt;/P&gt;</description>
    <pubDate>Fri, 07 May 2010 01:35:39 GMT</pubDate>
    <dc:creator>dhaffner</dc:creator>
    <dc:date>2010-05-07T01:35:39Z</dc:date>
    <item>
      <title>distributed search both ways?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12973#M1105</link>
      <description>&lt;P&gt;Is it possible to have indexer A distribute to indexer B and have B distribute to A?
What are the settings for it.  Just trying to set it up via the GUI, it all seems OK, but B cannot see any events on A.
Thanks for any help!&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 03:51:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12973#M1105</guid>
      <dc:creator>dhaffner</dc:creator>
      <dc:date>2010-05-06T03:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: distributed search both ways?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12974#M1106</link>
      <description>&lt;P&gt;Yes. You just set it up twice, repeating the steps on each side.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 04:02:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12974#M1106</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-06T04:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: distributed search both ways?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12975#M1107</link>
      <description>&lt;P&gt;That's what we have done, but it is only working one way, not both.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 04:14:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12975#M1107</guid>
      <dc:creator>dhaffner</dc:creator>
      <dc:date>2010-05-06T04:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: distributed search both ways?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12976#M1108</link>
      <description>&lt;P&gt;Any ideas why it doesn't work?  We've done it on 2 other indexers with no problems.  Where do we start looking?&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 04:51:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12976#M1108</guid>
      <dc:creator>dhaffner</dc:creator>
      <dc:date>2010-05-06T04:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: distributed search both ways?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12977#M1109</link>
      <description>&lt;P&gt;Have you checked whether the same field extractions exist on both servers? &lt;/P&gt;

&lt;P&gt;In distributed search the search-time knowledge that gets used is solely on the search head. 
so if the field extractions/lookups/eventtypes etc are different, you will get different results, and if your search uses one of the missing items, frequently 0 results.&lt;/P&gt;</description>
      <pubDate>Thu, 06 May 2010 05:14:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12977#M1109</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2010-05-06T05:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: distributed search both ways?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12978#M1110</link>
      <description>&lt;P&gt;Perfect!  this worked out great!  Thank you very much!&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 01:35:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/distributed-search-both-ways/m-p/12978#M1110</guid>
      <dc:creator>dhaffner</dc:creator>
      <dc:date>2010-05-07T01:35:39Z</dc:date>
    </item>
  </channel>
</rss>

