<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Export Splunk logs to another SH; search differentiation question in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655109#M226310</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/125586"&gt;@dkr3500&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can configure your stand-alone server as Search Head of all three systems.&lt;/P&gt;&lt;P&gt;When you run a search, you have a field "splunk_server" that tells you what's the Indexer where data are stored.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 22 Aug 2023 06:32:21 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-08-22T06:32:21Z</dc:date>
    <item>
      <title>How to Export Splunk logs to another SH; search differentiation question?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655062#M226292</link>
      <description>&lt;P&gt;This is a two parter:&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp; Is there a way to export Splunk logs from an indexer to an offline Splunk Search Head and conduct searches/create dashboards using those imported logs?&amp;nbsp; Is there a licensing issue with this approach?&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp; When exporting to the offline SH, I'd like to be able to differentiate which systems I'm searching/viewing in the dashboards - but my different test/dev/prod instances of the UFs that I'm pulling logs from will have the same IP address and hostnames.&amp;nbsp; Is there a way to differentiate which instance I'm searching/viewing when dumping those logs into the offline SH?&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 20:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655062#M226292</guid>
      <dc:creator>dkr3500</dc:creator>
      <dc:date>2023-08-21T20:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Export Splunk logs to another SH; search differentiation question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655063#M226293</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/125586"&gt;@dkr3500&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;by definition a Search Head is a Splunk Server that send searches to the Indexers, it does't have archived logs!&lt;/P&gt;&lt;P&gt;If you mean to send some logs to a stand-alone server to use for testing, you should extract logs in raw format from the production Indexers (using e.g. one of the Production Search Heads) and manually load them in the stand-alone server, but you need to reindex them, paying twice the license.&lt;/P&gt;&lt;P&gt;If you have to use the production logs only for development, you could use a Search Head, out of your production SHC and use it to develop dashboards and apps using the production data, but you have to protect it to avoid unwanted accesses to your production data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 16:54:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655063#M226293</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-21T16:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Export Splunk logs to another SH; search differentiation question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655065#M226294</link>
      <description>&lt;P&gt;Good day&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;!&amp;nbsp;&lt;/P&gt;&lt;P&gt;As always, thank you for setting me straight.&amp;nbsp; I forgot that that little important fact; the exported logs would still need to be exported to another indexer.&lt;/P&gt;&lt;P&gt;As for the second part of my question, please let me clarify.&amp;nbsp; I will have 3 different Splunk Enterprise environments, all identical to each other but completely segregated.&amp;nbsp; Is there a way I can put the raw logs from all 3 Splunk Enterprise environments into an offline Splunk Enterprise indexer/SH and still be able to differentiate which logs/searches/dashboard data is from which of the 3 environments?&lt;/P&gt;&lt;P&gt;Thank you sir!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 17:17:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655065#M226294</guid>
      <dc:creator>dkr3500</dc:creator>
      <dc:date>2023-08-21T17:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Export Splunk logs to another SH; search differentiation question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655109#M226310</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/125586"&gt;@dkr3500&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can configure your stand-alone server as Search Head of all three systems.&lt;/P&gt;&lt;P&gt;When you run a search, you have a field "splunk_server" that tells you what's the Indexer where data are stored.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 06:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655109#M226310</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-22T06:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to Export Splunk logs to another SH; search differentiation question?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655183#M226336</link>
      <description>&lt;P&gt;Yes, you could, but it really doesn't make sense.&amp;nbsp; You can just directly peer the new Search Head to every/any Indexer.&amp;nbsp; You can discriminate what lives/came-from where by examining the "splunk_server" value.&amp;nbsp; So whatever you do, you can add a splityby (... BY splunk_server) to keep the results separated.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 13:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Export-Splunk-logs-to-another-SH-search-differentiation/m-p/655183#M226336</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-08-22T13:45:51Z</dc:date>
    </item>
  </channel>
</rss>

