Getting Data In

Is it possible to run scripted input on the search peer?

aa70627
Communicator

Is it possible to run scripted input on the search peer? Also, is it possible to ensure it runs from all search peers ? Thanks ahead of time. 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @aa70627,

which scripted input are you speaking for?

in other words, what do you want t otake with it? local or remote logs?

if local, there isn't any problem, you can distribute it to all indexers via Master Node and the logs are indexed on the same Indexer.

If you're speaking of remote logs, there's the problem that you probably you need only one execution of the script and not more than one.

Could you better describe your need?

Ciao.

Giuseppe

View solution in original post

aa70627
Communicator

My initial question was for the scripted input logs within local server. I wanted to run a script form each indexer and send the data to splunk. I was able to confirm it works the same as a scripted input on UF or SH. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aa70627,

which scripted input are you speaking for?

in other words, what do you want t otake with it? local or remote logs?

if local, there isn't any problem, you can distribute it to all indexers via Master Node and the logs are indexed on the same Indexer.

If you're speaking of remote logs, there's the problem that you probably you need only one execution of the script and not more than one.

Could you better describe your need?

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...