Deployment Architecture

How do you search for all data on one index server in a cluster?

broberg
Communicator

We got a large Splunk distributed environment and for troubleshooting i want to search for all data in only one index server and not on the cluster.

I don't want the search or a search request to go to any of there other index servers.

Is this possible?

0 Karma
1 Solution

dkeck
Influencer

Hi,

just add a splunk_server=your indexer name

e.g. index=_internal splunk_server=your indexer name

to your search

View solution in original post

dkeck
Influencer

Hi,

just add a splunk_server=your indexer name

e.g. index=_internal splunk_server=your indexer name

to your search

dkeck
Influencer

Any luck with that?

If it helped please accept the answer 🙂 Thank you

0 Karma

broberg
Communicator

Hi, yes that actually worked. I thought it would send the search to all index servers but it actually did not. Thank you.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...