Getting Data In

REST API Query in Search Head Clustering

siva_cg
Path Finder

Hi All,

We have 8 search heads made them as cluster (Search Head Cluster). Also, we have indexer cluster with more than 20 indexers which are managed by Cluster Master. We use load balancer for the Search Head Cluster to distribute the users to Search Heads.

Now, I want to run a REST query which will give us the list of users logged in from all the search heads. If I run it normally, I am getting the results from local server only. But I want to get the details from all the Search Heads. I am aware that I can use Distributed Manager Console for these type of things but I have few other REST queries which are not in the DMC. Could you please help me in this issue?

Thanks in advance.

0 Karma

valiquet
Contributor
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...