Getting Data In

What are the federated search requirements for remote dataset?

FritzWittwer1
Path Finder

I am trying to setup a federated index, on a federated search head, but i am only able to select an index as the remote dataset. the drop down for dataset type does not offer any other option. How do i have to configure the dataset on the remote search head in order to be able to use it on the federated search head.

Bot systems are clustered search heads running Splunk enterprise 8.2.2

Labels (1)
Tags (1)
0 Karma

FritzWittwer1
Path Finder

Found the Answer, only indexes can be accessed with a federated search, see Create a federated index

Dataset SpecificationSpecify the Type of remote dataset that this federated index maps to and provide the Object Name for the dataset. Currently, only the Index dataset type is available.

For Object Name you must provide the name of an index that currently exists on the selected federated provider.
The dataset Type defaults to Index.

Object Name has no default.
 
 
 
0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...