Getting Data In

How can I pass Splunk output from one Splunk server to another?

harshal_chakran
Builder

Hi,

Is it possible that I have two Splunk servers running one at my office location which has historical data and other one in my laptop which I am carrying. If I fire some query for which data is available at office location but I want the result at my laptop. I understand that I can run Cloud service or have the data on Cloud and do this task easily. But my concern is, that I have slow speed internet on my laptop when I am travelling. So in that case, is it possible that I run a query for which the data is on Splunk server which is at office.

Also, on my laptop some other device will be dumping huge data and I want to correlate the data on laptop and data at my office location. And both locations have different Splunk servers.

Please advice.

0 Karma

kristian_kolb
Ultra Champion

You can most likely set up distributed searching, so that you configure your laptop Splunk instance to use the office Splunk as a Search Peer. That way it can search both instances and make the correlations.

http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Overviewofconfiguration

/K

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...