Splunk Search
Highlighted

How do subsearch work in distributed search?

Path Finder

Per my knowledge, the subsearch result would be acted as parameter to the main search. In the distributed search, would the subsearch result first be consolidated in the search head and then further distributed to the search peer? Thanks!

0 Karma
Highlighted

Re: How do subsearch work in distributed search?

Splunk Employee
Splunk Employee

Yes, it is exactly as you describe. The result is consolidated on the search head.

View solution in original post

Highlighted

Re: How do subsearch work in distributed search?

Communicator

Look at the job inspector it will give you some insight as to how the sub search works.

0 Karma
Highlighted

Re: How do subsearch work in distributed search?

Path Finder

Thanks all!
When distributed to the search peer, how do the results send out? via knowledge bundle?

0 Karma