Splunk Enterprise

Can Federated Search Results from Splunk Cloud to a Summary Index On-Premise?

dc595
Explorer

Hi,
Interested in knowing if  federated  search results from Splunk Cloud could be stored in a summary index located in a On-Premise Enterprise instance / cluster?

The thought is this could allow to offload some high usage dashboards to On-Premise  and allow for data correlation with On-premise data.   

Thank you

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...