Deployment Architecture

How to configure a local Splunk Server to search indexes on a remote server?

rbryan_wingspan
Engager

I have a new local install of Splunk that I want to use to develop dashboards without making changes to my production install of Splunk Enterprise.
I'd like for my local Splunk server to run queries against my production data without making a separate copy of the prod data.
Am I trying to make my local Splunk a peer, receiver, or some other term?

0 Karma

jmallorquin
Builder

Hi,

You have to configure in your local Splunk Settings > Distributed search > Search peers and add the conexion to your indexer.

Hope i help you.

0 Karma

somesoni2
Revered Legend

To be able to query data from a remote Splunk instance, you can add that Splunk instance (Indexer) as search peer to your local Splunk instance (Search Head). See this for more information on the same.

http://docs.splunk.com/Documentation/Splunk/6.2.6/DistSearch/Configuredistributedsearch

I would suggest to disable/remove can_delete capability from your local Splunk instance/Search head to avoid accidentally deleting production data.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...