<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to see data from a specific indexer in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48122#M11485</link>
    <description>&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;One more question: What is the value of this field: -the indexer hostname where the data got indexed originally or -the indexer hostname from which the data was sent to the search head for the current search?&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
Bartosz Maruszewski&lt;/P&gt;</description>
    <pubDate>Tue, 22 Feb 2011 18:53:28 GMT</pubDate>
    <dc:creator>tzhmaba2</dc:creator>
    <dc:date>2011-02-22T18:53:28Z</dc:date>
    <item>
      <title>How to see data from a specific indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48120#M11483</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Is there a way to search for data which has been sent to a specific indexer? I want to make a test (to check our recover scenario):&lt;BR /&gt;
- stop one indexer (even power off now)&lt;BR /&gt;
- unmount the SAN LUN whith index data and mount this LUN to another indexer&lt;BR /&gt;
- start splunk and clean or reindex the index&lt;BR /&gt;
- see if the data from the "broken" indexer are correctly seen on the test indexer.&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;

&lt;P&gt;Best regards,
Bartosz Maruszewski&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2011 00:08:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48120#M11483</guid>
      <dc:creator>tzhmaba2</dc:creator>
      <dc:date>2011-02-22T00:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to see data from a specific indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48121#M11484</link>
      <description>&lt;P&gt;You should have a field called "splunk_server", that's what indexer it came from.&lt;/P&gt;

&lt;P&gt;You should be able to search / display based on that.&lt;/P&gt;

&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2011 00:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48121#M11484</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2011-02-22T00:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to see data from a specific indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48122#M11485</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;One more question: What is the value of this field: -the indexer hostname where the data got indexed originally or -the indexer hostname from which the data was sent to the search head for the current search?&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
Bartosz Maruszewski&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2011 18:53:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48122#M11485</guid>
      <dc:creator>tzhmaba2</dc:creator>
      <dc:date>2011-02-22T18:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to see data from a specific indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48123#M11486</link>
      <description>&lt;P&gt;Its the indexer where the data was sent to from the forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2011 02:11:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48123#M11486</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2011-02-23T02:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to see data from a specific indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48124#M11487</link>
      <description>&lt;P&gt;Thanks very much!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2011 17:54:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48124#M11487</guid>
      <dc:creator>tzhmaba2</dc:creator>
      <dc:date>2011-02-24T17:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to see data from a specific indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48125#M11488</link>
      <description>&lt;P&gt;Do you know is there a way that we can tell a search to only distribute to a specific indexer? - The above solution will indeed show results from only one indexer. But i believe that the search is still distributed to all indexers, but only SHOWS results from the indexer specified.&lt;/P&gt;

&lt;P&gt;I am hoping to find a way to limit what indexer(s) the search is initially distributed to.&lt;/P&gt;

&lt;P&gt;Can anyone help here???&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;

&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2011 08:51:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-see-data-from-a-specific-indexer/m-p/48125#M11488</guid>
      <dc:creator>jdunlea_splunk</dc:creator>
      <dc:date>2011-12-08T08:51:38Z</dc:date>
    </item>
  </channel>
</rss>

