Deployment Architecture

How do you search for all data on one index server in a cluster?

broberg
Communicator

We got a large Splunk distributed environment and for troubleshooting i want to search for all data in only one index server and not on the cluster.

I don't want the search or a search request to go to any of there other index servers.

Is this possible?

0 Karma
1 Solution

dkeck
Influencer

Hi,

just add a splunk_server=your indexer name

e.g. index=_internal splunk_server=your indexer name

to your search

View solution in original post

dkeck
Influencer

Hi,

just add a splunk_server=your indexer name

e.g. index=_internal splunk_server=your indexer name

to your search

dkeck
Influencer

Any luck with that?

If it helped please accept the answer 🙂 Thank you

0 Karma

broberg
Communicator

Hi, yes that actually worked. I thought it would send the search to all index servers but it actually did not. Thank you.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...