Users in a distributed search setup
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Users in a distributed search setup
A distributed search requires Splunk user authentication for each server in the search.
Note A change to make LDAP user login names case-insensitive in 3.0.2 can cause problems with distributed search in an LDAP environment if there is a mix of 3.0.2 and 3.0.1 or 3.0 instances. Users with mixed case login names may or may not be able to see other instances, depending on which instance they first logged into after a Splunk restart. We recommend upgrading all instances to at least 3.0.2 if you are using LDAP and distributed search.
This documentation applies to the following versions of Splunk: 3.0 , 3.0.1 , 3.0.2 , 3.1 , 3.1.1 , 3.1.2 , 3.1.3 , 3.1.4 View the Article History for its revisions.