This documentation does not apply to the most recent version of Splunk.
This documentation applies to the following versions of Splunk: 3.0 , 3.0.1 , 3.0.2 , 3.1 , 3.1.1 , 3.1.2 , 3.1.3 , 3.1.4
A distributed search requires Splunk user authentication for each server in the search.
Note A change to make LDAP user login names case-insensitive in 3.0.2 can cause problems with distributed search in an LDAP environment if there is a mix of 3.0.2 and 3.0.1 or 3.0 instances. Users with mixed case login names may or may not be able to see other instances, depending on which instance they first logged into after a Splunk restart. We recommend upgrading all instances to at least 3.0.2 if you are using LDAP and distributed search.