Deployment Architecture

distsearch.conf and the web interface

hiddenkirby
Contributor

when configuring a distributed search ... why when i create a new server on the web interface it asks for a username:password though in distsearch.conf there isn't a place for it?

Is there something i am missing in the process of adding an indexer to the distsearch?

Is there a CLI step i have to do to add servers? or is having the list of servers under distsearch sufficient. (in the distsearch.conf)

i prefer not to use the UI if i have to... but it doesn't seem to work otherwise.

halp!

Thank you, Kirby

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

The password is not saved, and is not supposed to be saved. It is used once at the time of configuration to allow the local (search head) node to connect to the remote (indexer) node and ask it to accept its certificate, in order to allow trusted searches in the future.

If you use the GUI, there are no other steps. If you are doing it via the CLI, the steps, including where and how to copy the certificates, are here: http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Use_the_CLI

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The password is not saved, and is not supposed to be saved. It is used once at the time of configuration to allow the local (search head) node to connect to the remote (indexer) node and ask it to accept its certificate, in order to allow trusted searches in the future.

If you use the GUI, there are no other steps. If you are doing it via the CLI, the steps, including where and how to copy the certificates, are here: http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Use_the_CLI

0 Karma

fredclown
Builder
0 Karma

hiddenkirby
Contributor

Thank you. That cleared it up.

0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...