Deployment Architecture

distsearch.conf and the web interface

hiddenkirby
Contributor

when configuring a distributed search ... why when i create a new server on the web interface it asks for a username:password though in distsearch.conf there isn't a place for it?

Is there something i am missing in the process of adding an indexer to the distsearch?

Is there a CLI step i have to do to add servers? or is having the list of servers under distsearch sufficient. (in the distsearch.conf)

i prefer not to use the UI if i have to... but it doesn't seem to work otherwise.

halp!

Thank you, Kirby

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

The password is not saved, and is not supposed to be saved. It is used once at the time of configuration to allow the local (search head) node to connect to the remote (indexer) node and ask it to accept its certificate, in order to allow trusted searches in the future.

If you use the GUI, there are no other steps. If you are doing it via the CLI, the steps, including where and how to copy the certificates, are here: http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Use_the_CLI

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The password is not saved, and is not supposed to be saved. It is used once at the time of configuration to allow the local (search head) node to connect to the remote (indexer) node and ask it to accept its certificate, in order to allow trusted searches in the future.

If you use the GUI, there are no other steps. If you are doing it via the CLI, the steps, including where and how to copy the certificates, are here: http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Use_the_CLI

0 Karma

hiddenkirby
Contributor

Thank you. That cleared it up.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...