Getting Data In

Is it possible to set the default distributed search group on my search head to itself since it is also the indexer?

karabsze
Path Finder

Is it possible to set the default distributed search group to nothing but only search within itself (as my search head is also the indexer)?

If i set the distsearch.conf as below, the search request did not really execute on itself.

[distributedSearch:A]
default = false
servers = machineA:8089

[distributedSearch:B]
default = true
servers =

[distributedSearch]
servers = machineA:8089

1 Solution

karabsze
Path Finder

Finally, we setup like that to search itself too.

[distributedSearch:A]
default = false
servers = machineA:8089

[distributedSearch:B]
default = true
servers =localhost:localhost

[distributedSearch]
servers = machineA:8089, localhost:localhost

View solution in original post

karabsze
Path Finder

Finally, we setup like that to search itself too.

[distributedSearch:A]
default = false
servers = machineA:8089

[distributedSearch:B]
default = true
servers =localhost:localhost

[distributedSearch]
servers = machineA:8089, localhost:localhost

Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...