Deployment Architecture

Specify which server's _internal index to search

kogane
Path Finder

Is it possible to specify which server's _internal index to search? I have a setup with multiple search head pools, plus a license master with many slaves. My goal is to run a query from any search head, but have it use the _internal index of the license master only.

0 Karma

kristian_kolb
Ultra Champion

If you want to restrict searches to a particular server, you should tell it so;

index=_internal splunk_server=MY_SPLUNK_SERVER | blah blah

If you don't know the name of the server, you could probably find it out through a search like;

index=_internal | dedup splunk_server | table splunk_server

hope this helps,

Kristian

kristian_kolb
Ultra Champion

Well, I guess that you could either

a) define the license master as a search peer for all your search heads, or

b) configure the license master to forward its _internal logs to the indexer(s).

In case b) you'd then be looking at index=_internal host=your_license_master instead of splunk_server

/k

kogane
Path Finder

The license master is only a search head, not an indexer, so it doesn't show up in these results. It's not configured as a search peer, just as part of a search head pool. Perhaps I have to change this, to make what I want to do possible.

0 Karma

MarioM
Motivator

field splunk_server is the one which tell you which splunk instance the data come from

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...