Getting Data In

Is it possible to set the default distributed search group on my search head to itself since it is also the indexer?

karabsze
Path Finder

Is it possible to set the default distributed search group to nothing but only search within itself (as my search head is also the indexer)?

If i set the distsearch.conf as below, the search request did not really execute on itself.

[distributedSearch:A]
default = false
servers = machineA:8089

[distributedSearch:B]
default = true
servers =

[distributedSearch]
servers = machineA:8089

1 Solution

karabsze
Path Finder

Finally, we setup like that to search itself too.

[distributedSearch:A]
default = false
servers = machineA:8089

[distributedSearch:B]
default = true
servers =localhost:localhost

[distributedSearch]
servers = machineA:8089, localhost:localhost

View solution in original post

karabsze
Path Finder

Finally, we setup like that to search itself too.

[distributedSearch:A]
default = false
servers = machineA:8089

[distributedSearch:B]
default = true
servers =localhost:localhost

[distributedSearch]
servers = machineA:8089, localhost:localhost

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...