Splunk does such an awesome job with distributed search. It seems like all my data is on one server (my search head) when, in reality, Splunk is running searches against multiple indexing servers that I have configured as peers.
Is there some way for me to restrict my search to a particular peer?
The splunk_server field specifies the peer:
splunk_server=<peer_name>
You can use the value "local" to refer to the Splunk instance that you are searching from; in other words, the search head itself:
splunk_server=local
The splunk_server field specifies the peer:
splunk_server=<peer_name>
You can use the value "local" to refer to the Splunk instance that you are searching from; in other words, the search head itself:
splunk_server=local
See the splunk_server field, it tells you which indexer the event came from.