Deployment Architecture

How do you make sure that a specific index of the indexers can be searched from the search head?

superhm
Explorer

Hello.

In the distributed search function, I want to make sure that specific index of the indexers can be searched from the search head.

How can I do this?

ex)
- Search Head
- Indexer-1 : All indexes
- Indexer-2 : _audit (Just one index)

Thank you.

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

As far as I know you can't achieve this. When you create role on search head and assign specific indexes access & when you run search on search head in distributed environment, the search distribute to all the indexers so you can't restrict to only search _audit index from indexer2 and all indexes from indexer1.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

As far as I know you can't achieve this. When you create role on search head and assign specific indexes access & when you run search on search head in distributed environment, the search distribute to all the indexers so you can't restrict to only search _audit index from indexer2 and all indexes from indexer1.

0 Karma

superhm
Explorer

Thank you for your advice...

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...