Deployment Architecture

Distributed Search across multiple "separate" environments

MasterOogway
Communicator

I have two separate Splunk environments: 1) syslog data for platform group 2) network data for LAN & WAN

I don't want Env #1 doing a distributed search to #2 unless we are troubleshooting a specific outage. How can I easily turn on/off distributed searches between separate Splunk environments? Would it be as simple as adding the Indexing server #2 when troubleshooting and removing when done? Or is there a better method to have this capability? And if we have a third environment or fourth environment.....could it easily expand to search them all during troubleshooting times only?

Might be a "feature" for upcoming Splunk versions to offer options to turn "on/off" cross environment searching.

Master Oogway

Tags (1)
0 Karma

karabsze
Path Finder
0 Karma

LCM
Contributor

If nothing is defined (standard), all distributed peers will be searched. However, you'd be able to that with users & roles. Use different users, e.g. standard-user for "normal" use (in this case you have to limitate user/roles priveleges for "normal" user) and like a "debug-user" to troubleshoot (no limitation).

Have a look in these docus

Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...