Deployment Architecture

Cooperation between multiple splunk

krugger
Communicator

I have a working splunk server that has several indexes. I found out there is another department that is also using splunk, so I would like to use my splunk to search their splunk.

I was looking into distributed search, but it appear we would have to have a common shared folder to store our indexes.

What is the proper way to make the remote indexes appear in my splunk? I don't want all of them only a few.

I guess I have to configure my search head to go and query the remote splunk indexer. Any pointers on that?

Edit:
With distributed search enabled it seems every single search is also being done on the remote peer. How do I stop this from happening?

Tags (1)
0 Karma
1 Solution

okrabbe_splunk
Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

View solution in original post

0 Karma

rmcdougal
Path Finder

It should be as easy as adding their indexer as a search peer to your search head. Other than ensuring the management port is open between the two, that should be it.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Distributed search doesn't have to have the same index folders. You can set the other department as a search peer, and just specifiy index=foo for the ones you need off of their indexer. As long as any custom extractions are in both places, you should be ok with doing it this way.

0 Karma

krugger
Communicator

each splunk has its own custom extractions, as we are indexing different systems.

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...