Admin Manual

 


About the Splunk Admin Manual
How Splunk Works

How distributed search works

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

How distributed search works

Distributed search is a peer-to-peer configuration that enables one Splunk server to send searches across many other Splunk instances. Upon login, authentication attempts are federated across all other included servers. Users who want to search across distributed Splunk hosts must have the exact same credentials (username and password) on all the included servers. You can propagate user credentials using the information in this Community wiki topic.

Users can restrict any search to explicitly search only a subset of the servers.

30 admin13 distribsearch-dsearch.jpg

Each Splunk server in a distributed search configuration must have an Enterprise license.

Distributed search is typically used to:

Note: Distributed search uses the management port (default 8089), so SSL must be either off or on for all servers. By default, SSL is turned on for the management port. If you turn it off for one server, you must turn it off for all servers.

Known issues with distributed search

This documentation applies to the following versions of Splunk: 3.3 , 3.3.1 , 3.3.2 , 3.3.3 , 3.3.4 , 3.4 , 3.4.1 , 3.4.2 , 3.4.3 , 3.4.5 , 3.4.6 , 3.4.8 , 3.4.9 , 3.4.10 , 3.4.11 , 3.4.12 , 3.4.13 , 3.4.14 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!