CARVIEW |
Select Language
HTTP/2 200
date: Thu, 24 Jul 2025 23:28:13 GMT
content-type: text/html; charset=UTF-8
server: Apache
set-cookie: Apache=b59508aa.63ab52de81ddf; path=/; expires=Fri, 20-Jul-40 23:28:13 GMT; domain=.splunk.com
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
set-cookie: PHPSESSID=2f130708bae3f3997e1ee47a1404b65f; path=/
expires: Thu, 19 Nov 1981 08:52:00 GMT
cache-control: no-store, no-cache, must-revalidate
pragma: no-cache
set-cookie: ponydocs_session=2f130708bae3f3997e1ee47a1404b65f; path=/; secure; HttpOnly
x-xss-protection: 1; mode=block
referrer-policy: strict-origin-when-cross-origin
Splexicon:Distributedsearch - Splunk Documentation
We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website.
Learn more (including how to update your settings) here »
distributed search
distributed search
noun
A deployment topology that portions search management and search fulfillment/indexing activities across multiple Splunk Enterprise instances. In distributed search, a Splunk Enterprise instance, referred to as the search head, distributes search requests to other instances, called search peers, which perform the actual searching, as well as the data indexing. The search head merges the results back to the user.
Distributed search provides horizontal scaling, so that a single Splunk Enterprise deployment can search and index arbitrarily large amounts of data. Distributed search is also useful for correlating data across data silos.
Related terms
For more information
In the Distributed Deployment Manual:
In Distributed Search:
A
B
C
D
E
F
I
K
L
M
P
R
S
- saved search
- scheduled alert
- scheduled report
- scheduled search
- scheduler
- scripted authentication
- scripted input
- search
- search affinity
- Search app
- search artifact
- search assistant
- search execution directive
- search factor
- search field
- search filter
- search head
- search head cluster
- search head cluster captain
- search head cluster member
- search head clustering
- search head pooling
- search head targeting
- search job
- Search Job Inspector
- search macro
- search management
- search mode
- search peer
- search peer replication
- Search Processing Language
- search scheduler
- search time
- search timeline
- search view
- searchability
- searchable
- segment
- send to background
- sequence template
- series
- server
- server class
- Settings
- SignalFlow
- SignalFx Smart Agent receiver
- Simple XML
- single-instance deployment
- single-site indexer cluster
- SmartStore
- source
- source type
- span
- span tag
- SPL
- SPL2
- SPL2 statement
- Splunk Answers
- Splunk Distribution of OpenTelemetry Collector
- Splunk OpenTelemetry Collector
- Splunk platform
- Splunk UI
- Splunk Web
- Splunk Web Framework
- Splunkbase
- splunkd
- SplunkJS Stack
- stack mode
- standalone search head
- stanza
- static captain
- streaming command
- subsearch
- summary index
T
Closing this box indicates that you accept our Cookie Policy.