Deployment Architecture

Cooperation between multiple splunk

krugger
Communicator

I have a working splunk server that has several indexes. I found out there is another department that is also using splunk, so I would like to use my splunk to search their splunk.

I was looking into distributed search, but it appear we would have to have a common shared folder to store our indexes.

What is the proper way to make the remote indexes appear in my splunk? I don't want all of them only a few.

I guess I have to configure my search head to go and query the remote splunk indexer. Any pointers on that?

Edit:
With distributed search enabled it seems every single search is also being done on the remote peer. How do I stop this from happening?

Tags (1)
0 Karma
1 Solution

okrabbe_splunk
Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

View solution in original post

0 Karma

rmcdougal
Path Finder

It should be as easy as adding their indexer as a search peer to your search head. Other than ensuring the management port is open between the two, that should be it.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Distributed search doesn't have to have the same index folders. You can set the other department as a search peer, and just specifiy index=foo for the ones you need off of their indexer. As long as any custom extractions are in both places, you should be ok with doing it this way.

0 Karma

krugger
Communicator

each splunk has its own custom extractions, as we are indexing different systems.

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

You would configure distribued search:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Configuredistributedsearch

These easiest way to configure is probably through using the web UI.

Also, be sure to read about how authorization works for distributed searches so that you will be able to actually search the other indexer:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Howauthorizationworksindistributedsearches

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...