Splunk Enterprise

Allocate a scheduled search to all searcheads in a searchead cluster

sebastian_m
Engager

Hello there,

we use an alert action that has a lot of technical dependencies. In order to make sure that all searchheads are able to perform this alert action we would like to make a regular check of all of them. Our idea was to use a simple scheduled search that triggers the alert action on a regular basis as a test, to see if everything is fine.

The problem is, that we don't know if it is possible to force the searchhead captain to allocate this specific search to all members of its cluster. Otherwise we would only see if the member that coincidentally got the search functions properly.

Do you know of any way to achieve, that all members of a searchead cluster run a specific search?

Thanks in advance for the help.

0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

In normal situation captain sends search to one of members to run. You cannot specify in which node it runs or specify that it run every one.

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

In normal situation captain sends search to one of members to run. You cannot specify in which node it runs or specify that it run every one.

0 Karma

sebastian_m
Engager

That is unfortunate. But thanks for your reply.

0 Karma
Get Updates on the Splunk Community!

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...