Deployment Architecture

How do you search for all data on one index server in a cluster?

broberg
Communicator

We got a large Splunk distributed environment and for troubleshooting i want to search for all data in only one index server and not on the cluster.

I don't want the search or a search request to go to any of there other index servers.

Is this possible?

0 Karma
1 Solution

dkeck
Influencer

Hi,

just add a splunk_server=your indexer name

e.g. index=_internal splunk_server=your indexer name

to your search

View solution in original post

dkeck
Influencer

Hi,

just add a splunk_server=your indexer name

e.g. index=_internal splunk_server=your indexer name

to your search

dkeck
Influencer

Any luck with that?

If it helped please accept the answer 🙂 Thank you

0 Karma

broberg
Communicator

Hi, yes that actually worked. I thought it would send the search to all index servers but it actually did not. Thank you.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...