Override the default provider for a role

Users and administrators can override the search targeting for the list of default transparent mode federated providers that is configured for a role.

Users and administrators can override the search targeting for the list of default transparent mode federated providers that is configured for a role on the Providers tab, without changing the SPL in the search. This is useful when a search needs to run against a different provider than the role uses by default, which gives users flexibility if they have a different workflow for some searches.

You can override default provider targeting in the following ways:

  • For ad hoc searches: Use a Splunk API REST call with the federated_remote_providers parameter. The override applies only to that search job.

  • For saved searches: Use the federated_providers parameter in Advanced Edit in Splunk Web to target a specific provider for a saved search.