Topics

| pdf version

How Splunk Works


Splunk > The IT Search Company

  • Search and navigate IT data from applications, servers and network devices in real-time.
  • Download Splunk

Localized Splunk documentation

Looking for Splunk documentation in other languages?

Enable distributed search via SplunkWeb

This documentation does not apply to the most recent version of Splunk.

This documentation applies to the following versions of Splunk: 3.0 , 3.0.1 , 3.0.2 , 3.1 , 3.1.1 , 3.1.2 , 3.1.3 , 3.1.4

Enable distributed search via SplunkWeb

To enable distributed search via SplunkWeb:


  • Click the Admin link in the upper right hand corner

Image:Enabling distributed search via Splunk Web-admin.jpg


  • Select the Distributed tab, and click Distributed Search.

Image:Enabling distributed search via Splunk Web-distributed.jpg


To turn distributed search on:


  • Set the Distributed Searches to other Splunk servers? radio button to Yes.
  • If you want other Splunk instances to automatically find this instance, set the Auto-Discoverable? radio button to Yes.
    • Note: Discovered servers will not be displayed until the change has been committed and Splunk has been restarted.
  • Add the IP address and port number of the other Splunk instances that you want to include in the distributed search cluster. This port number must match the same splunkd port number as in the Admin / Server / Settings on the remote instance.
    • Note: If you enabled Auto discoverable on other Splunk instances they will be displayed in the Discovered Servers column. Each server will have an Add button next to it. Click Add to add the servers to cluster.
  • Click the Save button to commit the changes.
Revision: 207 | Contact | Privacy Policy | Terms of Use | Community content licensed under Creative Commons