Splunk Search

How can i exclude search peers by default in distributed search?

sonicZ
Contributor

We have multiple splunk servers accessed by two central search heads, and some of these splunk servers are spread out geographically.
Sometimes we get latency between some of the search peers and most of the time we are not searching these servers(for example our Australian splunk indexers)

Default behaviour in distsearch.conf seems to look for all search peers unless specified with a NOT splunk_server = is there a way to change the default to not include some indexers so you have to explicitly name them ?

Checking in the spec file i see an interesting line, would this do the trick?

disabled_servers = <comma separated list of servers>
 * A list of configured but disabled search peers.
Tags (2)
0 Karma

Damien_Dallimor
Ultra Champion

That is certainly my understanding of the usage of the "disabled_servers" property in distsearch.conf

You can also disable the search peer via Splunk Web :

Manager -> Distributed search -> Search peers -> Status : enabled|disabled

sonicZ
Contributor

Thanks Damien i forgot about disabling them in the search peers section, it looks like when they are disabled you cannot search on them explicitly though with splunk_server="name" would be nice to have that option to search splunk indexers on demand but keep them disabled a percentage of the time.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...