Splunk Search

distributed search both ways?

Path Finder

Is it possible to have indexer A distribute to indexer B and have B distribute to A? What are the settings for it. Just trying to set it up via the GUI, it all seems OK, but B cannot see any events on A. Thanks for any help!

Tags (2)
0 Karma
1 Solution

SplunkTrust
SplunkTrust

Have you checked whether the same field extractions exist on both servers?

In distributed search the search-time knowledge that gets used is solely on the search head. so if the field extractions/lookups/eventtypes etc are different, you will get different results, and if your search uses one of the missing items, frequently 0 results.

View solution in original post

SplunkTrust
SplunkTrust

Have you checked whether the same field extractions exist on both servers?

In distributed search the search-time knowledge that gets used is solely on the search head. so if the field extractions/lookups/eventtypes etc are different, you will get different results, and if your search uses one of the missing items, frequently 0 results.

View solution in original post

Path Finder

Perfect! this worked out great! Thank you very much!

0 Karma

Splunk Employee
Splunk Employee

Yes. You just set it up twice, repeating the steps on each side.

0 Karma

Path Finder

Any ideas why it doesn't work? We've done it on 2 other indexers with no problems. Where do we start looking?

0 Karma

Path Finder

That's what we have done, but it is only working one way, not both.

0 Karma