Searching Peers (Distributed Search)

When you run a search query, by default, only your local Logger is searched for matching events. However, you can specify in your query to run the search on the peer Loggers

Prerequisites

To perform peer searches and view their search results, you need the following groups and permissions:

Follow these guidelines for searching across peers:

Example queries for searching across peers:

Search that sorts five fields:

_peerLogger IN [“peer1”, “peer2”, …] | sort deviceEventCategory eventId deviceCustomNumber1 deviceCustomNumber2 deviceCustomNumber3

Search with field extraction:

_peerLogger IN [“peer1”, “peer2”, …] | rex "(?<src_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"

Search evaluating a variable:

_peerLogger IN [“peer1”, “peer2”, …] | eval (int)urllength=len(requestUrl) |sort urllength

Search with results grouped and counted as a top 50 list:

_peerLogger IN [“peer1”, “peer2”, …] | and priority > 0 | top 50 name

Search for events with a long URL:

_peerLogger IN [“peer1”, “peer2”, …] | eval n=len(requestUrl) | where n = "1023"

Concept Link IconSee Also