Splunk Search

How to achieve a federated search to link the on-prem indexers to the cloud SH?

andrew_burnett
Path Finder

I have a distributed Splunk environment, meaning a SHC and IDX cluster connected via distributed search as outlined in the Splunk docs. I have a Splunk Cloud free trial, and was wanting to try out federated search to link the on-prem indexers to the cloud SH. However, I cannot get it to work. Has anyone accomplished this before? How the docs outline it to be is that you place the federated search provider pointing at a SH rather than a IDX, and is there ports that need to be opened on the Cloud side?

Labels (1)
0 Karma

khourihan_splun
Splunk Employee
Splunk Employee

The free trial doesn't have the API port open, if I recall.  Can you ping the port ?  8089?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...