Hunk User Manual

Configure and run unified search

About unified search

Hunk archiving lets you search archived data in virtual archive indexes as well as the live data in the Splunk Enterprise indexes that feed those archives. Depending on how you configured archiving for your Splunk Enterprise indexes, your archived data may overlap with the unarchived data in your Splunk Enterprise indexes.

For example, we recommend that you set your Splunk Enterprise indexes to archive data before the data is set to be expunged from the Splunk enterprise index to avoid the risk of data being temporarily unavailable for search. This would create some data overlap.

You configure unified search for any virtual index that is also configured for archiving. Then, any time you run a search against that Splunk Enterprise index, unified search automatically checks data in both Splunk Enterprise indexes and archives, while skipping the duplicated data.

How to search with unified search

Unified search works only for indexes which are explicitly specified in the search. Unified search will not search archives for indexes that are implicitly specified, for example, via default index(es) or indexes specified via wildcards. Unified search does not sort by the event's create date, this includes results that only come from real Splunk indexers where data has not been archived yet. Hunk does not support real-time searches with unified search.

For more about how Hunk handles searches and time/dates, see Search a virtual index.

Here are some examples of explicit searches where unified search can help improve your searches:

  • index=myindex someterm
  • index=myindexname OR index=foo | top limit=20 “result.category_id”

Here are some examples of non-explicit searches that will not cause unified search to search archives:

  • wildcards
  • someterm
  • index=m* someterm
  • index!=my_splunk_index_with_an_archive
  • NOT index=my_splunk_index_with_an_archive

Configuring unified search

Important: to use unified search, the indexes must be defined on the search head as well as indexers. If indexes are not defined in the search head Splunk creates empty indexes

Turn on unified search in limits.conf by setting unified_search to true:

# turn on/off feature
unified_search = true

In indexes.conf add the following attribute to your index archive stanza:

[myindex_archive] = = <window length, before present time, in seconds>

A query against myindex will automatically look for events older than this cutoff in the archive index (i.e. myindex_archive), and will look for younger events in myindex itself. We recommend putting the unified search cutoff to occur right before the Splunk index is configured to move buckets from the cold state to the frozen state.

See About archiving Splunk indexes for more about archive configuration.

Here's an example of a virtual index configured to use unified search:

[root@sandbox bin]# more $SPLUNK_HOME/etc/apps/search/local/limits.conf 
unified_search = true

[root@sandbox bin]# more $SPLUNK_HOME/etc/apps/search/local/indexes.conf 
vix.output.buckets.from.indexes = myindex
vix.output.buckets.older.than = 3600
vix.output.buckets.path = /user/root/archive/myindex_archive
vix.provider = hdp2provider = 14400
# 14400 is 4 hours
Last modified on 05 April, 2016
Configure data model acceleration   Troubleshoot Hunk

This documentation applies to the following versions of Hunk®(Legacy): 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11

Was this topic useful?

You must be logged into in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters