Getting Data In

How can I pass Splunk output from one Splunk server to another?

harshal_chakran
Builder

Hi,

Is it possible that I have two Splunk servers running one at my office location which has historical data and other one in my laptop which I am carrying. If I fire some query for which data is available at office location but I want the result at my laptop. I understand that I can run Cloud service or have the data on Cloud and do this task easily. But my concern is, that I have slow speed internet on my laptop when I am travelling. So in that case, is it possible that I run a query for which the data is on Splunk server which is at office.

Also, on my laptop some other device will be dumping huge data and I want to correlate the data on laptop and data at my office location. And both locations have different Splunk servers.

Please advice.

0 Karma

kristian_kolb
Ultra Champion

You can most likely set up distributed searching, so that you configure your laptop Splunk instance to use the office Splunk as a Search Peer. That way it can search both instances and make the correlations.

http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Overviewofconfiguration

/K

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...