Splunk Cloud Platform

Can Splunk Cloud search on-prem indexers using federated search?

jordanking1992
Path Finder

Hello,

In a cloud migration, can a Splunk Cloud Search Head be configured to search both its cloud data and legacy data on-prem indexers?

Ex. There's an on-prem index called 'index01' that contains historical data. There is also same index created in Splunk Cloud with 90 days of data. After switching the UF's to point to Splunk Cloud, is there a way to run a search in Splunk Cloud that searches the recent 90 days of data in the cloud + the historical on-prem data?

In this scenario, it seems like it would be Splunk Cloud - > On-Prem but this blog does not have that option.
https://www.splunk.com/en_us/blog/platform/introducing-splunk-federated-search.html

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, Federated Search works from Cloud to on-prem.  See the docs at https://docs.splunk.com/Documentation/Splunk/9.0.4/Search/Aboutfederatedsearch#Kinds_of_federated_se...

Usually, however, a migration to Splunk Cloud includes moving historical data to the cloud so Federated Search (FS) is not needed.  There are a number of caveats to FS so you should approach it carefully.

FS will not search cloud for recent data and on-prem for historical.  Instead, every search is sent to both the Cloud and on-prem indexers. 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...