Deployment Architecture

How do you search for all data on one index server in a cluster?

broberg
Communicator

We got a large Splunk distributed environment and for troubleshooting i want to search for all data in only one index server and not on the cluster.

I don't want the search or a search request to go to any of there other index servers.

Is this possible?

0 Karma
1 Solution

dkeck
Influencer

Hi,

just add a splunk_server=your indexer name

e.g. index=_internal splunk_server=your indexer name

to your search

View solution in original post

dkeck
Influencer

Hi,

just add a splunk_server=your indexer name

e.g. index=_internal splunk_server=your indexer name

to your search

dkeck
Influencer

Any luck with that?

If it helped please accept the answer 🙂 Thank you

0 Karma

broberg
Communicator

Hi, yes that actually worked. I thought it would send the search to all index servers but it actually did not. Thank you.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...