Getting Data In

REST API Query in Search Head Clustering

siva_cg
Path Finder

Hi All,

We have 8 search heads made them as cluster (Search Head Cluster). Also, we have indexer cluster with more than 20 indexers which are managed by Cluster Master. We use load balancer for the Search Head Cluster to distribute the users to Search Heads.

Now, I want to run a REST query which will give us the list of users logged in from all the search heads. If I run it normally, I am getting the results from local server only. But I want to get the details from all the Search Heads. I am aware that I can use Distributed Manager Console for these type of things but I have few other REST queries which are not in the DMC. Could you please help me in this issue?

Thanks in advance.

0 Karma

valiquet
Contributor
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...