Getting Data In

Is it possible to set the default distributed search group on my search head to itself since it is also the indexer?

karabsze
Path Finder

Is it possible to set the default distributed search group to nothing but only search within itself (as my search head is also the indexer)?

If i set the distsearch.conf as below, the search request did not really execute on itself.

[distributedSearch:A]
default = false
servers = machineA:8089

[distributedSearch:B]
default = true
servers =

[distributedSearch]
servers = machineA:8089

1 Solution

karabsze
Path Finder

Finally, we setup like that to search itself too.

[distributedSearch:A]
default = false
servers = machineA:8089

[distributedSearch:B]
default = true
servers =localhost:localhost

[distributedSearch]
servers = machineA:8089, localhost:localhost

View solution in original post

karabsze
Path Finder

Finally, we setup like that to search itself too.

[distributedSearch:A]
default = false
servers = machineA:8089

[distributedSearch:B]
default = true
servers =localhost:localhost

[distributedSearch]
servers = machineA:8089, localhost:localhost

Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...