Deployment Architecture

distsearch.conf and the web interface

hiddenkirby
Contributor

when configuring a distributed search ... why when i create a new server on the web interface it asks for a username:password though in distsearch.conf there isn't a place for it?

Is there something i am missing in the process of adding an indexer to the distsearch?

Is there a CLI step i have to do to add servers? or is having the list of servers under distsearch sufficient. (in the distsearch.conf)

i prefer not to use the UI if i have to... but it doesn't seem to work otherwise.

halp!

Thank you, Kirby

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

The password is not saved, and is not supposed to be saved. It is used once at the time of configuration to allow the local (search head) node to connect to the remote (indexer) node and ask it to accept its certificate, in order to allow trusted searches in the future.

If you use the GUI, there are no other steps. If you are doing it via the CLI, the steps, including where and how to copy the certificates, are here: http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Use_the_CLI

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The password is not saved, and is not supposed to be saved. It is used once at the time of configuration to allow the local (search head) node to connect to the remote (indexer) node and ask it to accept its certificate, in order to allow trusted searches in the future.

If you use the GUI, there are no other steps. If you are doing it via the CLI, the steps, including where and how to copy the certificates, are here: http://www.splunk.com/base/Documentation/latest/Admin/Configuredistributedsearch#Use_the_CLI

0 Karma

fredclown
Builder
0 Karma

hiddenkirby
Contributor

Thank you. That cleared it up.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...