Getting Data In

Help with Interview prep

alexlexxy
Explorer

Describe what happens when an adhoc search is issued on a search head in a distributed environment?

Does the search head communicate with the cluster master or directly with the indexers? Im looking for clarifications. 

Labels (1)
0 Karma
1 Solution

alexlexxy
Explorer

@venkatasri  thank you for the response, however,  I was just wondering what will happen if the cluster master goes down, will the SH be able to return results of an adhoc search?

0 Karma

alexlexxy
Explorer

Totally! thank you.

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@alexlexxy  SH does communicate with cluster master before finding out which peers to fetch results.

more detailed notes here,

https://docs.splunk.com/Documentation/Splunk/8.2.2/Indexer/Howclusteredsearchworks#Search_across_a_s...

 

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of Splunk APM’s and Splunk RUM’s streaming infrastructure in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...