Splunk Search

Can Splunk Federated Search be configured for bidirectional search?

meetmshah
SplunkTrust
SplunkTrust

I want to configure Federated Search so that Deployment A can search Deployment B, and Deployment B can also search Deployment A. I understand that Federated Search is typically unidirectional (local search head → remote provider). Is it possible to configure it for true bidirectional searches in a single architecture (create two separate unidirectional configurations (A→B and B→A))?

Has anyone implemented this setup successfully? Any best practices or caveats would be appreciated.

Also, have anyone implemented this along with ITSI - what are the takeaways and do & don'ts?

Labels (1)
0 Karma

PrewinThomas
Motivator

@meetmshah 

I haven't tested this personally. But theoratically by creating two separate unidirectional configurations its feasible. Deployment A acts as a Federated Search Head with Deployment B as its Federated Provider and deployment B also acts as a Federated Search Head with Deployment A as its Federated Provider.

As per document Real-time searches are not supported in Federated Search mode.
#https://docs.splunk.com/Documentation/ITSI/4.20.1/EA/FedSearch

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

meetmshah
SplunkTrust
SplunkTrust

Thanks for the answer @livehybrid. With respect to - "Yes two different deployments can be fed. search clients for eachother"? - Have you seen an environment with the same? Because I couldn't find any of the Splunk Doc where it's mentioned that the environments can be interconnected.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @meetmshah 

Yes two different deployments can be fed. search clients for eachother - however the connections will not really know of each other. 

I dont know too much about the best practices here, however *Federated Search for Splunk supports Splunk IT Service Intelligence version 4.16.0 and higher, for transparent mode federated search only* based on the docs.

Note - the federated search docs suggest engaging with your account team and/or support when working with premium apps such as ITSI with federated search.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...