Deployment Architecture

distsearch.conf and the web interface

hiddenkirby
Contributor

when configuring a distributed search ... why when i create a new server on the web interface it asks for a username:password though in distsearch.conf there isn't a place for it?

Is there something i am missing in the process of adding an indexer to the distsearch?

Is there a CLI step i have to do to add servers? or is having the list of servers under distsearch sufficient. (in the distsearch.conf)

i prefer not to use the UI if i have to... but it doesn't seem to work otherwise.

halp!

Thank you, Kirby

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

The password is not saved, and is not supposed to be saved. It is used once at the time of configuration to allow the local (search head) node to connect to the remote (indexer) node and ask it to accept its certificate, in order to allow trusted searches in the future.

If you use the GUI, there are no other steps. If you are doing it via the CLI, the steps, including where and how to copy the certificates, are here: http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Use_the_CLI

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The password is not saved, and is not supposed to be saved. It is used once at the time of configuration to allow the local (search head) node to connect to the remote (indexer) node and ask it to accept its certificate, in order to allow trusted searches in the future.

If you use the GUI, there are no other steps. If you are doing it via the CLI, the steps, including where and how to copy the certificates, are here: http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Use_the_CLI

0 Karma

hiddenkirby
Contributor

Thank you. That cleared it up.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...