Splunk Search

How to achieve a federated search to link the on-prem indexers to the cloud SH?

andrew_burnett
Path Finder

I have a distributed Splunk environment, meaning a SHC and IDX cluster connected via distributed search as outlined in the Splunk docs. I have a Splunk Cloud free trial, and was wanting to try out federated search to link the on-prem indexers to the cloud SH. However, I cannot get it to work. Has anyone accomplished this before? How the docs outline it to be is that you place the federated search provider pointing at a SH rather than a IDX, and is there ports that need to be opened on the Cloud side?

Labels (1)
0 Karma

khourihan_splun
Splunk Employee
Splunk Employee

The free trial doesn't have the API port open, if I recall.  Can you ping the port ?  8089?

0 Karma
Get Updates on the Splunk Community!

Message Parsing in SOCK

Introduction This blog post is part of an ongoing series on SOCK enablement. In this blog post, I will write ...

Exploring the OpenTelemetry Collector’s Kubernetes annotation-based discovery

We’ve already explored a few topics around observability in a Kubernetes environment -- Common Failures in a ...

Use ‘em or lose ‘em | Splunk training units do expire

Whether it’s hummus, a ham sandwich, or a human, almost everything in this world has an expiration date. And, ...