<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can Splunk Federated Search be configured for bidirectional search? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-Federated-Search-be-configured-for-bidirectional/m-p/750655#M242392</link>
    <description>&lt;P&gt;I want to configure Federated Search so that Deployment A can search Deployment B, and Deployment B can also search Deployment A. I understand that Federated Search is typically unidirectional (local search head → remote provider). Is it possible to configure it for true bidirectional searches in a single architecture (create two separate unidirectional configurations (A→B and B→A))?&lt;/P&gt;&lt;P&gt;Has anyone implemented this setup successfully? Any best practices or caveats would be appreciated.&lt;/P&gt;&lt;P&gt;Also, have anyone implemented this along with ITSI - what are the takeaways and do &amp;amp; don'ts?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jul 2025 16:26:44 GMT</pubDate>
    <dc:creator>meetmshah</dc:creator>
    <dc:date>2025-07-29T16:26:44Z</dc:date>
    <item>
      <title>Can Splunk Federated Search be configured for bidirectional search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-Federated-Search-be-configured-for-bidirectional/m-p/750655#M242392</link>
      <description>&lt;P&gt;I want to configure Federated Search so that Deployment A can search Deployment B, and Deployment B can also search Deployment A. I understand that Federated Search is typically unidirectional (local search head → remote provider). Is it possible to configure it for true bidirectional searches in a single architecture (create two separate unidirectional configurations (A→B and B→A))?&lt;/P&gt;&lt;P&gt;Has anyone implemented this setup successfully? Any best practices or caveats would be appreciated.&lt;/P&gt;&lt;P&gt;Also, have anyone implemented this along with ITSI - what are the takeaways and do &amp;amp; don'ts?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 16:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-Federated-Search-be-configured-for-bidirectional/m-p/750655#M242392</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2025-07-29T16:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk Federated Search be configured for bidirectional search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-Federated-Search-be-configured-for-bidirectional/m-p/750693#M242401</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258346"&gt;@meetmshah&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes two different deployments can be fed. search clients for eachother - however the connections will not really know of each other.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont know too much about the best practices here, however *F&lt;SPAN&gt;ederated Search for Splunk supports Splunk IT Service Intelligence version 4.16.0 and higher, for transparent mode federated search only* based on the &lt;A href="https://help.splunk.com/en/splunk-enterprise/search/federated-search/10.0/run-federated-searches-across-other-splunk-deployments/about-federated-search-for-splunk" target="_self"&gt;docs&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Note - the &lt;A href="https://docs.splunk.com/Documentation/SVA/current/Architectures/FederatedSearch" target="_self"&gt;federated search docs&lt;/A&gt; suggest engaging with your account team and/or support when working with premium apps such as ITSI with federated search.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 21:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-Federated-Search-be-configured-for-bidirectional/m-p/750693#M242401</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-29T21:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk Federated Search be configured for bidirectional search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-Federated-Search-be-configured-for-bidirectional/m-p/750712#M242404</link>
      <description>&lt;P&gt;Thanks for the answer&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;. With respect to - "&lt;SPAN&gt;Yes two different deployments can be fed. search clients for eachother"? -&amp;nbsp;Have you seen an environment with the same? Because I couldn't find any of the Splunk Doc where it's mentioned that the environments can be interconnected.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2025 07:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-Federated-Search-be-configured-for-bidirectional/m-p/750712#M242404</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2025-07-30T07:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk Federated Search be configured for bidirectional search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-Federated-Search-be-configured-for-bidirectional/m-p/750716#M242405</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258346"&gt;@meetmshah&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't tested this personally. But theoratically by creating two separate unidirectional configurations its feasible. Deployment A acts as a Federated Search Head with Deployment B as its Federated Provider and deployment B also acts as a Federated Search Head with Deployment A as its Federated Provider.&lt;/P&gt;&lt;P&gt;As per document Real-time searches are not supported in Federated Search mode.&lt;BR /&gt;#&lt;A href="https://docs.splunk.com/Documentation/ITSI/4.20.1/EA/FedSearch" target="_blank"&gt;https://docs.splunk.com/Documentation/ITSI/4.20.1/EA/FedSearch&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2025 07:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Can-Splunk-Federated-Search-be-configured-for-bidirectional/m-p/750716#M242405</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-30T07:46:41Z</dc:date>
    </item>
  </channel>
</rss>

