Deployment Architecture

Cooperation between multiple splunk

Communicator

I have a working splunk server that has several indexes. I found out there is another department that is also using splunk, so I would like to use my splunk to search their splunk.

I was looking into distributed search, but it appear we would have to have a common shared folder to store our indexes.

What is the proper way to make the remote indexes appear in my splunk? I don't want all of them only a few.

I guess I have to configure my search head to go and query the remote splunk indexer. Any pointers on that?

Edit:
With distributed search enabled it seems every single search is also being done on the remote peer. How do I stop this from happening?

Tags (1)
0 Karma
1 Solution

Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

View solution in original post

0 Karma

Path Finder

It should be as easy as adding their indexer as a search peer to your search head. Other than ensuring the management port is open between the two, that should be it.

0 Karma

SplunkTrust
SplunkTrust

Distributed search doesn't have to have the same index folders. You can set the other department as a search peer, and just specifiy index=foo for the ones you need off of their indexer. As long as any custom extractions are in both places, you should be ok with doing it this way.

0 Karma

Communicator

each splunk has its own custom extractions, as we are indexing different systems.

0 Karma

Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

View solution in original post

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!