Deployment Architecture

Distributed Search using a VIP ip address on an HA pair to another HA Pair

tier2ops
Explorer

So I have two ha pairs that I want to set distributes searches on:

Pair-A-1 10.10.10.5
Pair-A-2 10.10.10.6
VIP 10.10.10.7

Pair-B-1 172.16.1.11
Pair-B-2 172.16.1.12
VIP 172.16.1.13

How do I setup the peers?

Pair-A-1:

Peer 172.16.1.13:8089 (By Vip)

or

Peer Pair-B-1:8089 (or Peer 172.16.1.11:8089)

Peer Pair-B-2:8089 (or Peer 172.16.1.12:8089)

Tags (1)

araitz
Splunk Employee
Splunk Employee

If I understand you question correctly, you will need to share the search head's distsearch key out to each of the nodes:

http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Distribute_the_key_...

After that, your distsearch.conf should look something like this:

[distributedSearch]
heartbeatFrequency = 10
servers = 10.10.10.7:8089,172.16.1.13:8089
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...