Deployment Architecture

Attributes to be set in distsearch.conf

username021
Explorer

I read that the distsearch.conf is to configure only distributed search.
In order to set the distributed search , I have set the distsearch.conf ENABLED in my Splunkweb(Search head).
It creates the file in the Search head --> (distsearch.conf)

In my deployment , I have

deployment server-1

heavy forwarder-1

Indexers -2

Do i need to add all the Splunk instance(incl. forwarder,deployment server) in 'servers' attribute ? or only the search head IPs ?

distsearch.conf

 #This file contains possible attributes and values you can use to configure distributed search.
[distributedSearch]
servers = 10.x.x.x:8089,10.x.x.x:8089
0 Karma

adityapavan18
Contributor

In distsearch.conf

in Servers you need to add only search-peers(Indexers or where data is being stored)

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...