distributed search

noun

A deployment topology that portions search management and search fulfillment/indexing activities across multiple Splunk instances. In distributed search, a Splunk instance, referred to as the search head, distributes search requests to other Splunk instances, called search peers, which perform the actual searching, as well as the data indexing. The search head then merges the results back to the user. Distributed search provides horizontal scaling, making it possible to search and index hundreds of gigabytes or terabytes per day. Additionally, distributed search is useful for correlating data across different data silos.

Related terms

For more information

In the Distributed Deployment Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time