Splunk Search

Default splunk_server_group

beaunewcomb
Communicator

Scenario:  Two large organizations with two separate Splunk implementations.  Org A acquires Org B and in a consolidation effort they'd like to consolidate their search heads and search 2 indexer clusters.

What are some approaches to this?  One caveat is both Org A and Org B have some overlapping index names (ie both have index=network).

Is it possible to give a role a "default" cluster, so anytime OrgA user searches, they default to OrgA, BUT can be overridden by specifying splunk_server_group=OrgB or splunk_server_group=* ?

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

A search head can search multiple indexer clusters.  That's a supported configuration.  Separate clusters will always have some overlapping index names (such as _internal). 

It's up to the user to filter the desired results when search data comes from more than one cluster.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...