...ll $SPLUNK/etc/system/local distsearch.conf files were purged, and the app contains some peers on distsearch.conf and clustered indexers on server.conf Recently we found one cluster member stubbornly k...
Does anyone have any examples of regex used in the Blacklist patterns for distsearch.conf? We are trying to limit what gets replicated in distributed searches and I thought this would be a good s...
Hi, We have 3 search head in a cluster and 3 indexers in non clustered environment. Whenever we do a rolling restart of the SH, the distsearch.conf in etc/system/local and some lookup csv in s...
in the distsearch.conf on our search head we can blacklist applications [replicationBlacklist] splunk_app1_blacklist = apps/splunk_app1/... splunk_app2_blacklist = apps/splunk_app2/... W...
Hello I need a small clarification over distsearch.conf.
As per the documentation, to connect the SH with Indexer. One can configure in SH using any of the 3 ways : CLI, GUI & Conf file. T...
...et's call it etc/apps/searchhead). Looking at my files, most of them should be fine, but I was wondering about the syntax for the distsearch.conf lookups. What I have now is like: l...
I read that the distsearch.conf is to configure only distributed search. In order to set the distributed search , I have set the distsearch.conf ENABLED in my Splunkweb(Search head).
It creates t...
...433773905.807685 Timed out waiting for peer spkidx001.iggroup.local. If this occurs frequently, receiveTimeout in distsearch.conf may need to be increased. Search results might be incomplete!
06-08-2...