<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search on distributed splunk servers in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52192#M12672</link>
    <description>&lt;P&gt;No, but you can do the same configuration on the other server, i.e. tell it to use the other as a search peer.&lt;/P&gt;

&lt;P&gt;Then they can search each other, but they will not share configs for field extractions, lookups, saved searches etc etc.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
    <pubDate>Tue, 15 May 2012 20:27:42 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2012-05-15T20:27:42Z</dc:date>
    <item>
      <title>search on distributed splunk servers</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52188#M12668</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
  I installed splunk on 2 servers, e.g. abc and xyz and I am able to access it from &lt;A href="http://abc:8000/"&gt;http://abc:8000/&lt;/A&gt; and &lt;A href="http://xyz:8000/"&gt;http://xyz:8000/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So the question is how can I perform a search on &lt;A href="http://abc:8000/"&gt;http://abc:8000/&lt;/A&gt; and the search universe including both abc and xyz.&lt;/P&gt;

&lt;P&gt;I tried to enter splunk_server=xyz on &lt;A href="http://abc:8000/"&gt;http://abc:8000/&lt;/A&gt; but no data is returned. Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2012 16:12:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52188#M12668</guid>
      <dc:creator>shangshin</dc:creator>
      <dc:date>2012-05-15T16:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: search on distributed splunk servers</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52189#M12669</link>
      <description>&lt;P&gt;You need to set up the distsearch.conf on each server if you want to query data from both of them.  See the documentation on distributed search:  &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.2/Deploy/Configuredistributedsearch"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.2/Deploy/Configuredistributedsearch&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2012 16:25:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52189#M12669</guid>
      <dc:creator>bjalex80</dc:creator>
      <dc:date>2012-05-15T16:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: search on distributed splunk servers</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52190#M12670</link>
      <description>&lt;P&gt;You go into Manager -&amp;gt; Distributed Search -&amp;gt; Search Peers -&amp;gt; Add&lt;/P&gt;

&lt;P&gt;Then you fill out the form and press Save. You need to know the admin-password for the Splunk server you are connecting to, and they need to be able to communicate on port 8089 (or whatever you changed it to (if you did)).&lt;/P&gt;

&lt;P&gt;For more information see the docs,&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2012 16:29:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52190#M12670</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-05-15T16:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: search on distributed splunk servers</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52191#M12671</link>
      <description>&lt;P&gt;Thanks for the advice. I followed your instruction and see all the data is available on one server. I assume by adding a peer server, I am able to search data across distributed splunk server. &lt;/P&gt;

&lt;P&gt;However, lookup fields or sourcetype created on distributed server won't be visiable on the local server. Is that correct?&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2012 18:46:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52191#M12671</guid>
      <dc:creator>shangshin</dc:creator>
      <dc:date>2012-05-15T18:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: search on distributed splunk servers</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52192#M12672</link>
      <description>&lt;P&gt;No, but you can do the same configuration on the other server, i.e. tell it to use the other as a search peer.&lt;/P&gt;

&lt;P&gt;Then they can search each other, but they will not share configs for field extractions, lookups, saved searches etc etc.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2012 20:27:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-on-distributed-splunk-servers/m-p/52192#M12672</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-05-15T20:27:42Z</dc:date>
    </item>
  </channel>
</rss>

