Back to Floor
The Search Network • Room 1

Distributed Search Architecture

In a distributed environment, the Search Head sends search requests to Search Peers (indexers). Each peer searches its local data and returns results to the Search Head, which merges them.

The Search Head distributes search knowledge (saved searches, field extractions, macros) to peers via knowledge bundles — compressed packages replicated automatically.

distsearch.conf on the Search Head defines which servers are search peers and how knowledge bundles are replicated.

Add a search peer via CLI
./splunk add search-server https://indexer1:8089
  -auth admin:password -remoteUsername admin
  -remotePassword password

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
❤️❤️❤️
Question 1 of 2
What does a Search Head send to Search Peers?
ARaw data
BIndex buckets
CSearch requests
DLicense tokens