Deployment Architecture

Do I need to configure distributed search on all the search peers?

lguinn2
Legend

Do I need to configure distributed search on all the search peers?

Tags (1)
2 Solutions

jrodman
Splunk Employee
Splunk Employee

On your search head, you can add each search peer within manager, while providing credentials to log into each peer. This is all you need for the search head to successfully search on the peers (search nodes).

There are other things you may want to do surrounding getting the data fanned out across the indexing & search nodes, but that should be it for distributed search setup itself.

View solution in original post

0 Karma

the_wolverine
Champion

No, a search peer does not have to be configured to use distributed search. It must, however, be distributed search-enabled so that other peers can add it.

View solution in original post

0 Karma

the_wolverine
Champion

No, a search peer does not have to be configured to use distributed search. It must, however, be distributed search-enabled so that other peers can add it.

0 Karma

jrodman
Splunk Employee
Splunk Employee

On your search head, you can add each search peer within manager, while providing credentials to log into each peer. This is all you need for the search head to successfully search on the peers (search nodes).

There are other things you may want to do surrounding getting the data fanned out across the indexing & search nodes, but that should be it for distributed search setup itself.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...