Splunk Search

Remote search head to assist local search heads?

Kindred
Path Finder

We currently have a single Splunk search+indexer locally, and 4 remote indexers in different countries.

As we started setting up a new dedicated search head we noticed as we added the remote indexers the speed of the searches was taking longer and longer to run. These remote indexers do not store much data in comparison to the local indexer, but it's increasing the runtime 10x.

Is this because of latency/bandwidth issues to the remote indexers? If so, is it possible to install remote search heads purely to help with searching those remote indexers, so that the local search head queries the remote search head for requesting data, rather than querying the individual remote indexers?

Tags (1)
0 Karma

antlefebvre
Communicator

What is the bandwidth to those sites? Since the remote indexers do not store much data, you may want to forward that data to the local indexer or set up a separate indexer locally to allow a search to that server with higher bandwidth. If you forward that data with splunktcp from the remote indexers you will be assured that the information gets there eventually over the slower links.

0 Karma

antlefebvre
Communicator

It sounds very strange. If you search for * you will get all the raw data. Which you could then export. So leaving the data at the indexers but being allowed to search them provides no security whatsoever.

0 Karma

Kindred
Path Finder

Bandwidth isn't too bad (upto 1mbit/s) but can be worse at times. It's mainly the latency which is a good 300-400ms and may have packet loss at times.

We can't forward data out of those sites for ownership/security reasons (as strange as it sounds) or we wouldn't have used remote indexers in the first place.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...