Splunk Search

With a distributed index and search environment do any searches need to be enabled on the indexers

kbecker
Communicator

In our distributed environment I noticed that our index servers have the following saved searches enabled. Can these be disabled since we have a dedicated search server?

Top five sourcetypes Indexing workload

Thanks...

Tags (3)
1 Solution

sideview
SplunkTrust
SplunkTrust

Yes you can go ahead and disable those if nobody is going to use the web interface on those servers directly.

View solution in original post

sideview
SplunkTrust
SplunkTrust

Yes you can go ahead and disable those if nobody is going to use the web interface on those servers directly.

Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...