Security

Dispatch_rest_to_indexers

Poojitha
Path Finder

Hi All,

I have a question. What exactly 'Dispatch_rest_to_indexers' mean ?

I am getting warning when running rest command and I am on splunk cloud.
Restricting results of the "rest" operator to the local instance because you do not have the "dispatch_rest_to_indexers" capability.

I see many blogs talking about this message but I did not come across clear explanation on what does this parameter exactly mean ? Dispatch_rest_to_indexers . What does this exactly do ?

Please can anyone throw some light on this .

Thanks in Advance,
PNV

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

This capability does (almost) exactly what it says - lets you dispatch a REST call (via the | rest command) to the indexers (to configured search peers, to be precise - in some cases (typically a Monitoring Console) you might want to REST against a non-indexer peer). Without it you can only call |rest to your local instance.

As far as I remember, that capability is not available for users in Cloud.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
It’s available on Splunk’s own cloud engineers not for any customers, not even for role sc_admin.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...