Splunk Search

Is there a way to do a Splunk query on data spread across different splunk instances?

manus
Communicator

Is there a way to do a Splunk query on data spread across different splunk instances? I guess not.
If not, is there any feature worth knowing, which would ease data aggregation between different Splunk instances?

0 Karma

yannK
Splunk Employee
Splunk Employee

Once you have the search-head configured to search on your indexers, you can look at the actual number of events repartition per indexer.

index=* | chart count by index splunk_server

FYI about deployment with multiple indexers and a search-head
- you only need a single license and define a license-master.
- you can configure your forwarders to loadbalance the data to the indexers
- more indexers means a better loadbalancing and faster searches (map-reduce)

0 Karma

gfuente
Motivator

The solution is having just one splunk instance (with many indexers as part of the same Splunk instance or arquitecture) as big as needed with all the data.

I think this is on purpose to avoid having a small license in tons of servers and query them all.

Regards

0 Karma

somesoni2
SplunkTrust
SplunkTrust

You would be able to add different Splunk instances as Search Peer to your search head. This will allow you to run your query across search peers. See this
http://docs.splunk.com/Documentation/Splunk/6.2.0/DistSearch/Whatisdistributedsearch

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...