hi All,
We have indexer cluster with 10 Idx. Is it possible to run a search query for every 15 mins with a time range of last 15 mins as a schedule job at indexer level and the results of this job into an index =result_summary.
If its possible can someone help me with the steps on how to achieve it?
Thanks,
Sree
not sure whether you wan the search head to search a particular indexer or the indexer to search itself. the
for an indexer to search itself, you can save a search on the indexer, will not recommend that approach.
you can specify the indexer a search head will search from by using the splunk_server
field
for example, in your 10 indexers cluster, search number 7 only:
index = <your_index> sourcetype = <your_sourcetype> splunk_server = indexer_7 .... | evals and stats | ... | collect <new_summary_index ...
hope it helps
Thanks Adonio!
We have a cluster of indexers of 10 Idx. Is it possible to schedule it at indexer level and it can be run on any indexers?
Thanks,
Sreedhar
please elaborate on your use case?
i mean yes you can login to an indexer and run a search and then save it and schedule it, it will run only on that particular indexer.
why would you like to do so? you can have the same thing done from your search head and add the filter splunk_server = <your_indexer>
to your search. the search will run against that indexer only.
Thanks Adonio!
What happens if my indexer 7 is down due to some unavoided scenario when the scheduled serach is supposed to run.
index = sourcetype = splunk_server = indexer_7 .... | evals and stats | ... | collect
if you execute the search on the seach head it will return no results with the warning that " ... peer might be "Down" ... check ... "