Splunk Search

How to see data from a specific indexer

tzhmaba2
Path Finder

Hi,

Is there a way to search for data which has been sent to a specific indexer? I want to make a test (to check our recover scenario):
- stop one indexer (even power off now)
- unmount the SAN LUN whith index data and mount this LUN to another indexer
- start splunk and clean or reindex the index
- see if the data from the "broken" indexer are correctly seen on the test indexer.

Any ideas?

Best regards, Bartosz Maruszewski

Tags (2)
0 Karma
1 Solution

Brian_Osburn
Builder

You should have a field called "splunk_server", that's what indexer it came from.

You should be able to search / display based on that.

Brian

View solution in original post

jdunlea_splunk
Splunk Employee
Splunk Employee

Do you know is there a way that we can tell a search to only distribute to a specific indexer? - The above solution will indeed show results from only one indexer. But i believe that the search is still distributed to all indexers, but only SHOWS results from the indexer specified.

I am hoping to find a way to limit what indexer(s) the search is initially distributed to.

Can anyone help here???

Thanks!

John

0 Karma

Brian_Osburn
Builder

You should have a field called "splunk_server", that's what indexer it came from.

You should be able to search / display based on that.

Brian

tzhmaba2
Path Finder

Thanks very much!

0 Karma

Brian_Osburn
Builder

Its the indexer where the data was sent to from the forwarder.

0 Karma

tzhmaba2
Path Finder

Thanks!

One more question: What is the value of this field: -the indexer hostname where the data got indexed originally or -the indexer hostname from which the data was sent to the search head for the current search?

Best regards,
Bartosz Maruszewski

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...