Set up Federated Search for Splunk between Splunk platform deployments

Complete the following steps to set up Federated Search for Splunk between a local deployment and a remote deployment.

Note: To run federated searches, Splunk Cloud Platform deployments require additional configuration from Splunk Support. This is true whether the Splunk Cloud Platform deployment is on the local or remote side of the federated search. If you are setting up federated search between two Splunk Cloud Platform deployments, you must contact Splunk Support for both deployments.
If you have a support contract, file a new case using the Splunk Support Portal at Support and Services. Otherwise, contact Customer Support.
Number Task For more information
1 Determine the federated provider mode of the remote deployment. See About the standard and transparent modes
2 Set up a service account on the remote deployment. See Service accounts and security for Federated Search for Splunk
3 Apply a federated provider definition to the remote deployment. Set the provider mode. See Define a Splunk platform federated provider
4 If you have defined a standard mode federated provider, define one or more federated indexes for it. See Map a federated index to a remote Splunk dataset
5 If you have defined a standard mode federated provider and you intend to run federated searches that are dependent on custom knowledge objects, ensure those knowledge objects exist on the remote search head. See Manage knowledge objects for standard mode federated providers
6 Run federated searches. See Run federated searches over remote Splunk platform deployments