<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In a Distributed Search environment, how do I restrict my search to a particular peer or peers? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/In-a-Distributed-Search-environment-how-do-I-restrict-my-search/m-p/10838#M596</link>
    <description>&lt;P&gt;See the splunk_server field, it tells you which indexer the event came from.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Apr 2010 07:09:43 GMT</pubDate>
    <dc:creator>oreoshake</dc:creator>
    <dc:date>2010-04-02T07:09:43Z</dc:date>
    <item>
      <title>In a Distributed Search environment, how do I restrict my search to a particular peer or peers?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/In-a-Distributed-Search-environment-how-do-I-restrict-my-search/m-p/10837#M595</link>
      <description>&lt;P&gt;Splunk does such an awesome job with distributed search.  It seems like all my data is on one server (my search head) when, in reality, Splunk is running searches against multiple indexing servers that I have configured as peers.  &lt;/P&gt;

&lt;P&gt;Is there some way for me to restrict my search to a particular peer?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2010 05:44:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/In-a-Distributed-Search-environment-how-do-I-restrict-my-search/m-p/10837#M595</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-04-02T05:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: In a Distributed Search environment, how do I restrict my search to a particular peer or peers?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/In-a-Distributed-Search-environment-how-do-I-restrict-my-search/m-p/10838#M596</link>
      <description>&lt;P&gt;See the splunk_server field, it tells you which indexer the event came from.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2010 07:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/In-a-Distributed-Search-environment-how-do-I-restrict-my-search/m-p/10838#M596</guid>
      <dc:creator>oreoshake</dc:creator>
      <dc:date>2010-04-02T07:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: In a Distributed Search environment, how do I restrict my search to a particular peer or peers?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/In-a-Distributed-Search-environment-how-do-I-restrict-my-search/m-p/10839#M597</link>
      <description>&lt;P&gt;The splunk_server field specifies the peer:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk_server=&amp;lt;peer_name&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can use the value "local" to refer to the Splunk instance that you are searching from; in other words, the search head itself:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk_server=local
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 07 Apr 2010 11:19:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/In-a-Distributed-Search-environment-how-do-I-restrict-my-search/m-p/10839#M597</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-04-07T11:19:57Z</dc:date>
    </item>
  </channel>
</rss>

