I have a custom search command that can only be executed in a specific Splunk indexer. I need to run this search command from the master head. The main constrain I have is that the custom search command must run in a DMZ network area.
If I enable streaming=true the custom search will be distributed across all the splunk indexer. Therefore, the query will fail in the splunk indexers that cannot execute the custom search and it will take a lot of time to complete the execution.
If I try:
I get this error:
Error in 'customsearch' command: This command must be the first command of a search
Master head: Version 4.3
Indexer: Version 4.2.1
The search command is just a WEB REST call then the result set is presented to the user. This Web REST call can only be executed in the DMZ environment "The indexer is found in this environment". That is why, I need to exclude the indexers that cannot access this network.