Deployment Architecture

Cooperation between multiple splunk

krugger
Communicator

I have a working splunk server that has several indexes. I found out there is another department that is also using splunk, so I would like to use my splunk to search their splunk.

I was looking into distributed search, but it appear we would have to have a common shared folder to store our indexes.

What is the proper way to make the remote indexes appear in my splunk? I don't want all of them only a few.

I guess I have to configure my search head to go and query the remote splunk indexer. Any pointers on that?

Edit:
With distributed search enabled it seems every single search is also being done on the remote peer. How do I stop this from happening?

Tags (1)
0 Karma
1 Solution

okrabbe_splunk
Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

View solution in original post

0 Karma

rmcdougal
Path Finder

It should be as easy as adding their indexer as a search peer to your search head. Other than ensuring the management port is open between the two, that should be it.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Distributed search doesn't have to have the same index folders. You can set the other department as a search peer, and just specifiy index=foo for the ones you need off of their indexer. As long as any custom extractions are in both places, you should be ok with doing it this way.

0 Karma

krugger
Communicator

each splunk has its own custom extractions, as we are indexing different systems.

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...