<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Searching local indexes on a search head? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121136#M32587</link>
    <description>&lt;P&gt;This seems to be a recent change that came in with v6.4.  I have found if you add the following to the beginning of your search it will include the search head and all other servers.   &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; splunk_server=*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 05 May 2016 10:34:14 GMT</pubDate>
    <dc:creator>bmunson_splunk</dc:creator>
    <dc:date>2016-05-05T10:34:14Z</dc:date>
    <item>
      <title>Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121126#M32577</link>
      <description>&lt;P&gt;We have a test server that's indexing data locally (with sufficient license to do so).   For some development effort, we also have a need to make it a search head against our 4 production search peers.&lt;/P&gt;

&lt;P&gt;Yes, the index where all the test data is going on the test server is "main".&lt;/P&gt;

&lt;P&gt;I modified the configuration on this test server to use the search peers which has worked fine, but now searches on this test server no longer see the local events at all -- only events from the search peers.&lt;/P&gt;

&lt;P&gt;I'm not able to find much of any information about local indexes on a search head, so I'm not clear if this is because you can't really search local indexes once an instance becomes a search head, or if it's because the index on the search head is "main" and that index is also on the search peers and Splunk won't work with both.&lt;/P&gt;

&lt;P&gt;I may have no option but to disable the search peers on the test server, but I'd like to understand what the problem is.&lt;/P&gt;

&lt;P&gt;=== UPDATE&lt;BR /&gt;
OK, so apparently the characterization of this issue that I was given by the user wasn't accurate.   They aren't actually using 'main', but 2 separate unique indexes locally.  And also, apparently, their searches are working, just taking a bit longer.  I pointed out that it's because now with more open-ended searches, Splunk has more indexes/peers to look at and potentially more data to return so refining the locations that are searched is in order.&lt;/P&gt;

&lt;P&gt;This would actually have been more interesting had their been events in 'main', but I suspect that Splunk might have done the right thing there too.&lt;/P&gt;

&lt;P&gt;Thanks for pointing out the splunk_server field!&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 14:12:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121126#M32577</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2014-09-11T14:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121127#M32578</link>
      <description>&lt;P&gt;If you start this search on your test server (over a long time duration):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=main
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What do you get in the field splunk_server? Are there only your 4 production machines in there, or also the search head?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 15:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121127#M32578</guid>
      <dc:creator>tom_frotscher</dc:creator>
      <dc:date>2014-09-11T15:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121128#M32579</link>
      <description>&lt;P&gt;What just came up my mind: can a search head be its own search peer? In other words, what will happen if you add localhost:8089 as search peer on this search head?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 15:43:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121128#M32579</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-09-11T15:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121129#M32580</link>
      <description>&lt;P&gt;I do indeed get the splunk_server values I would expect, but as I just mentioned/updated, it looks like the events in question are not in 'main'.   I suspect that Splunk would probably "do the right thing" in that situation and return events from all 'main' indexes.&lt;/P&gt;

&lt;P&gt;I wouldn't think that Splunk could be explicitly named as its own search peer.   It kind of is already, isn't it?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 18:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121129#M32580</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2014-09-11T18:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121130#M32581</link>
      <description>&lt;P&gt;Responded by tom_frotscher as a comment. Please accept the answer to mark the question as resolved.&lt;/P&gt;

&lt;P&gt;you can specify the splunk indexer name  "splunk_server"&lt;BR /&gt;
&lt;CODE&gt;index=* splunk_server=&amp;lt;mysearchheadhostname&amp;gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:33:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121130#M32581</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-28T17:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121131#M32582</link>
      <description>&lt;P&gt;Just as addition: you can add &lt;CODE&gt;localhost:8089&lt;/CODE&gt; as search peer. But it will through some errors in splunkd.log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunkd.log:09-12-2014 07:19:36.480 +0200 WARN  DistributedPeerManager - Unable to distribute to peer named somehostname.FQDN.here at uri &lt;A href="https://localhost:8089" target="test_blank"&gt;https://localhost:8089&lt;/A&gt; because peer has status = "Duplicate Servername".
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 12 Sep 2014 05:22:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121131#M32582</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-09-12T05:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121132#M32583</link>
      <description>&lt;P&gt;Huh.   Interesting.  Nice to know it can handle it, but also that it knows it's kind of not right.  Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2014 13:17:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121132#M32583</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2014-09-12T13:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121133#M32584</link>
      <description>&lt;P&gt;Per the answer, when I ran the index=main search over a long time, I did only get the 4 production search peers in the splunk_server field.   Per my update, since I found out later that the test server had only unique indexes on it and never used 'main', that actually made sense.   Seems to be doing what I need/expect.  Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2014 13:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121133#M32584</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2014-09-12T13:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121134#M32585</link>
      <description>&lt;P&gt;Seems this behavior changed at some point with one of the Splunk releases. It used to default to search locally even if distributed search peers were defined. i.e. it would search local and remote indexes by default. It's a pain to have to prefix searches with "splunk_server=" for environments with a test or staging search head/indexer combo that also searches production indexers. I'd like to see the as an option in a .conf file to turn local search on/off.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2015 15:48:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121134#M32585</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2015-03-18T15:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121135#M32586</link>
      <description>&lt;P&gt;Splunk, please add this option back like it was in previous releases!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2015 17:03:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121135#M32586</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2015-04-30T17:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Searching local indexes on a search head?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121136#M32587</link>
      <description>&lt;P&gt;This seems to be a recent change that came in with v6.4.  I have found if you add the following to the beginning of your search it will include the search head and all other servers.   &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; splunk_server=*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 05 May 2016 10:34:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Searching-local-indexes-on-a-search-head/m-p/121136#M32587</guid>
      <dc:creator>bmunson_splunk</dc:creator>
      <dc:date>2016-05-05T10:34:14Z</dc:date>
    </item>
  </channel>
</rss>

