Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Splunk 9.x Enterprise Certified Admin Guide

You're reading from  Splunk 9.x Enterprise Certified Admin Guide

Product type Book
Published in Aug 2023
Publisher Packt
ISBN-13 9781803230238
Pages 256 pages
Edition 1st Edition
Languages
Author (1):
Srikanth Yarlagadda Srikanth Yarlagadda
Profile icon Srikanth Yarlagadda

Table of Contents (17) Chapters

Preface Part 1: Splunk System Administration
Chapter 1: Getting Started with the Splunk Enterprise Certified Admin Exam Chapter 2: Splunk License Management Chapter 3: Users, Roles, and Authentication in Splunk Chapter 4: Splunk Forwarder Management Chapter 5: Splunk Index Management Chapter 6: Splunk Configuration Files Chapter 7: Exploring Distributed Search Part 2:Splunk Data Administration
Chapter 8: Getting Data In Chapter 9: Configuring Splunk Data Inputs Chapter 10: Data Parsing and Transformation Chapter 11: Field Extractions and Lookups Chapter 12: Self-Assessment Mock Exam Index Other Books You May Enjoy

Configuring distributed search

The distributed search feature requires configuration to establish connectivity from the search head to indexers or search peers. From a standalone search head and indexer architecture to a large-scale multisite clustering setup, all implementations make use of the distributed search feature. Refer to the deployment type in Figure 7.2, which has three search heads in a cluster, enabling distributed search to interact with three independent indexers. Indexers receive data from various sources, such as universal forwarders, syslog inputs, and technology add-ons for indexing. Here are a few essential points to understand about distributed search:

  • Search heads are preconfigured to send queries to search peers upon user request.
  • Search heads consolidate the results received from peers that participate in the search.
  • Search heads present the results to the user.
  • A continuous background process called knowledge bundle replication runs (you...
lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}