Splunk Search

Federated Search Questions- Authentication option and Indexers?

jonaclough
Path Finder

Regarding Federated search:

  • Is the only authentication option username and password? We use SSO on the remote search head (LDAP/Reverse Proxy) which would be preferable.
  • Why do you need to explicitly define each remote index on the FSH? Why don’t Splunk allow you to enable all indexes and save the effort of having the maintain the list
Tags (1)
0 Karma
1 Solution

tej57
Builder

Hey @jonaclough,

For the first question, you'll have to use the username and password combination only for connecting to the remote search head. You can use a service account user created for federated search activities. 

For second question, I believe it is good to have one to one mapping for index from a security point of view. Not all indexes are required to be allowed/searched on the federated search. Only the required ones as per the use cases can be added.

View solution in original post

0 Karma

nejmeddine
Loves-to-Learn

can i use federated search between different versions splunk?

0 Karma

tej57
Builder

Hey @nejmeddine ,

Federated search can work on different Splunk versions as far as backward compatibility meets. You can find the same on the document below:

https://docs.splunk.com/Documentation/Splunk/9.0.4/Search/Aboutfederatedsearch#Kinds_of_federated_se...

 

- Hope this helps..!! 🙂

0 Karma

tej57
Builder

Hey @jonaclough,

For the first question, you'll have to use the username and password combination only for connecting to the remote search head. You can use a service account user created for federated search activities. 

For second question, I believe it is good to have one to one mapping for index from a security point of view. Not all indexes are required to be allowed/searched on the federated search. Only the required ones as per the use cases can be added.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...