Deployment Architecture

Cooperation between multiple splunk

krugger
Communicator

I have a working splunk server that has several indexes. I found out there is another department that is also using splunk, so I would like to use my splunk to search their splunk.

I was looking into distributed search, but it appear we would have to have a common shared folder to store our indexes.

What is the proper way to make the remote indexes appear in my splunk? I don't want all of them only a few.

I guess I have to configure my search head to go and query the remote splunk indexer. Any pointers on that?

Edit:
With distributed search enabled it seems every single search is also being done on the remote peer. How do I stop this from happening?

Tags (1)
0 Karma
1 Solution

okrabbe_splunk
Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

View solution in original post

0 Karma

rmcdougal
Path Finder

It should be as easy as adding their indexer as a search peer to your search head. Other than ensuring the management port is open between the two, that should be it.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Distributed search doesn't have to have the same index folders. You can set the other department as a search peer, and just specifiy index=foo for the ones you need off of their indexer. As long as any custom extractions are in both places, you should be ok with doing it this way.

0 Karma

krugger
Communicator

each splunk has its own custom extractions, as we are indexing different systems.

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...