Splunk Search

How can we search indexes in Splunk EnvironmentA (Unix) from another Splunk EnvironmentB (Windows) and vice versa?

rsathish47
Contributor

Hi All,

We have two different Splunk environment one is Unix and another is in Windows. Is their way to read (search) the indexes cross platform. Please let us know how to configure this.

Thanks
Sathish Rangan

sduff_splunk
Splunk Employee
Splunk Employee

Hi Sathish,

You can move the index files between Unix and Windows systems. The main thing you need to be concerned about is that you can't move buckets created by a 64-bit version of Splunk to a system running 32-bit.

Instructions for doing so can be found at http://docs.splunk.com/Documentation/Splunk/6.2.4/Indexer/Moveanindex . Also read the following Splunk > answers post, http://answers.splunk.com/answers/32176/is-it-possible-to-migrate-indexed-buckets-to-a-different-ind...

Cheers,
Simon

rsathish47
Contributor

Thank you sduff,

But we dont want to move the index just want to read(search) the data from another platform(search head)

Thanks
Sathish Rangan

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Ah, OK, if I understand you, Splunk does that easily.

You want to use Distributed Search, which configures your search head to query the data stored on the indexers. http://docs.splunk.com/Documentation/Splunk/6.2.4/DistSearch/Configuredistributedsearch#Use_Splunk_W...

There are no issues with different OSs or environments communicating with one another.

rsathish47
Contributor

thank you sduff .. will try that.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...