Splunk
  • Splunk Enterprise

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    Splunk Cloud Platform

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    Splunkbase

    Discover, share, and install apps and add-ons with the Splunk community on Splunkbase. Publish your own or add others to your Splunk platform instance.

    DATA MANAGEMENT

    • Common Information Model
    • Data Manager
    • DB Connect
    • Edge Processing
    • Forwarders
    • Indexing
    • Ingest Monitoring
    • Stream
    • Technical Add-Ons

    SEARCH AND ANALYTICS

    • AI Toolkit
    • Alerts
    • Analytics Workspace
    • Dashboard Studio
    • Federated Search
    • Knowledge Objects
    • Search and Reporting App
    • Simple XML Dashboards
    • SPL
    • SPL2

    ADMINISTRATION

    • Cloud Platform
    • Enterprise
  • Enterprise Security

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    SOAR

    Streamline your security operations with a SOAR system that integrates orchestration, playbook automation, and case management to enhance threat response.

    ENTERPRISE SECURITY

    • Enterprise Security 8
    • Enterprise Security 7
    • Mission Control
    • Security Content Update
    • User Behavior Analytics

    SOAR

    • SOAR On-Premises
    • SOAR Cloud
    • App for SOAR
    • App for SOAR Export
    • Automation Broker

    RELATED APPS

    • Attack Analyzer
    • Asset and Risk Intelligence
    • App for PCI Compliance
    • App for Fraud Analytics
    • InfoSec App
    • Security Essentials
  • IT Service Intelligence

    Prevent disruptions and optimize operations when you monitor and analyze your IT service with predictive analytics and machine learning.

    Release Notes

    Content Packs

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    ITSI

    • Event Analytics
    • Entity Integration
    • Modules
    • Service Insights
    • REST APIs

    IT Ops

    • IT Essentials Work
    • IT Essentials Learn

    ADMINISTRATION

    • IT Service Intelligence
    • IT Essentials Work
    • Configuration File Reference

    EXTENSIONS

    • SAP Solutions
    • Infrastructure Monitoring Add-On
  • Splunk Observability Cloud

    Gain end-to-end visibility, troubleshoot in real-time, and optimize performance across infrastructure, applications, and user interfaces.

    Release Notes

    MONITORING

    • Alerts and Detectors
    • Application Performance Monitoring
    • Infrastructure Monitoring
    • Observability Cloud for Mobile
    • On-Call

    DATA MANAGEMENT

    • AI Assistant
    • Dashboards and Charts
    • Integrations
    • Log Observer Connect
    • Metrics, Metadata, and Events
    • OpenTelemetry Collector
    • SignalFlow Analytics
    • Search Reference

    ADMINISTRATION

    • Organization Management
    • FedRamp Support
    • App Development
    • API Reference
  • AppDynamics SaaS

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    AppDynamics On-Premises

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    SAP Agent

    An on-premises solution using AppDynamics On-Premises or Appdynamics Virtual Appliance (self hosted).

    Release Notes

    ESSENTIALS

    • Alert and Respond
    • Agent Management
    • Dashboards and Reports
    • Extensions
    • Licensing
    • Tag Management

    MONITORING

    • Analytics
    • Application Security Monitoring
    • Application Performance Monitoring
    • Database Visibility
    • End User Monitoring
    • Infrastructure Visibility

    ADMINISTRATION

    • AppDynamics SaaS
    • AppDynamics On-premises
  • Developer Documentation

    Build and deliver apps and integrations with SDKs, APIs and tools.

    Splunkbase

    Access and share apps and add-ons with the Splunk community on Splunkbase. Publish your own apps, or download and install others on your Splunk platform instance.

    PLATFORM

    • Developer Guide
    • APIs and tools
    • Tutorials
    • Downloads
    • Examples

    OBSERVABILITY

    • Developer Guide
    • REST APIs

    REFERENCE

    • Python 3 Migration
    • SOAR
    • SDK Reference
    • UI Toolkit
  • Resources

    Explore information on best practices, connect with community, or contact support.

    REFERENCE

    • Configuration Files Reference
    • REST APIs
    • SPL Reference
    • Splunk Style Guide
    • Search Tutorial
    • Validated Architectures

    Learn More

    • Free Trials & Downloads
    • Splunk Community
    • Splunk Answers
    • SPL 2 Reference
    • Splunk Lantern

    Support

    • AppDynamics Support
    • Cisco Support
    • Product Security Advisories
    • Splunk Support
    • System Status
English Japanese
English Japanese
  • Splunk Enterprise

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    Splunk Cloud Platform

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    Splunkbase

    Discover, share, and install apps and add-ons with the Splunk community on Splunkbase. Publish your own or add others to your Splunk platform instance.

    DATA MANAGEMENT

    • Common Information Model
    • Data Manager
    • DB Connect
    • Edge Processing
    • Forwarders
    • Indexing
    • Ingest Monitoring
    • Stream
    • Technical Add-Ons

    SEARCH AND ANALYTICS

    • AI Toolkit
    • Alerts
    • Analytics Workspace
    • Dashboard Studio
    • Federated Search
    • Knowledge Objects
    • Search and Reporting App
    • Simple XML Dashboards
    • SPL
    • SPL2

    ADMINISTRATION

    • Cloud Platform
    • Enterprise
  • Enterprise Security

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    SOAR

    Streamline your security operations with a SOAR system that integrates orchestration, playbook automation, and case management to enhance threat response.

    ENTERPRISE SECURITY

    • Enterprise Security 8
    • Enterprise Security 7
    • Mission Control
    • Security Content Update
    • User Behavior Analytics

    SOAR

    • SOAR On-Premises
    • SOAR Cloud
    • App for SOAR
    • App for SOAR Export
    • Automation Broker

    RELATED APPS

    • Attack Analyzer
    • Asset and Risk Intelligence
    • App for PCI Compliance
    • App for Fraud Analytics
    • InfoSec App
    • Security Essentials
  • IT Service Intelligence

    Prevent disruptions and optimize operations when you monitor and analyze your IT service with predictive analytics and machine learning.

    Release Notes

    Content Packs

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    ITSI

    • Event Analytics
    • Entity Integration
    • Modules
    • Service Insights
    • REST APIs

    IT Ops

    • IT Essentials Work
    • IT Essentials Learn

    ADMINISTRATION

    • IT Service Intelligence
    • IT Essentials Work
    • Configuration File Reference

    EXTENSIONS

    • SAP Solutions
    • Infrastructure Monitoring Add-On
  • Splunk Observability Cloud

    Gain end-to-end visibility, troubleshoot in real-time, and optimize performance across infrastructure, applications, and user interfaces.

    Release Notes

    MONITORING

    • Alerts and Detectors
    • Application Performance Monitoring
    • Infrastructure Monitoring
    • Observability Cloud for Mobile
    • On-Call

    DATA MANAGEMENT

    • AI Assistant
    • Dashboards and Charts
    • Integrations
    • Log Observer Connect
    • Metrics, Metadata, and Events
    • OpenTelemetry Collector
    • SignalFlow Analytics
    • Search Reference

    ADMINISTRATION

    • Organization Management
    • FedRamp Support
    • App Development
    • API Reference
  • AppDynamics SaaS

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    AppDynamics On-Premises

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    SAP Agent

    An on-premises solution using AppDynamics On-Premises or Appdynamics Virtual Appliance (self hosted).

    Release Notes

    ESSENTIALS

    • Alert and Respond
    • Agent Management
    • Dashboards and Reports
    • Extensions
    • Licensing
    • Tag Management

    MONITORING

    • Analytics
    • Application Security Monitoring
    • Application Performance Monitoring
    • Database Visibility
    • End User Monitoring
    • Infrastructure Visibility

    ADMINISTRATION

    • AppDynamics SaaS
    • AppDynamics On-premises
  • Developer Documentation

    Build and deliver apps and integrations with SDKs, APIs and tools.

    Splunkbase

    Access and share apps and add-ons with the Splunk community on Splunkbase. Publish your own apps, or download and install others on your Splunk platform instance.

    PLATFORM

    • Developer Guide
    • APIs and tools
    • Tutorials
    • Downloads
    • Examples

    OBSERVABILITY

    • Developer Guide
    • REST APIs

    REFERENCE

    • Python 3 Migration
    • SOAR
    • SDK Reference
    • UI Toolkit
  • Resources

    Explore information on best practices, connect with community, or contact support.

    REFERENCE

    • Configuration Files Reference
    • REST APIs
    • SPL Reference
    • Splunk Style Guide
    • Search Tutorial
    • Validated Architectures

    Learn More

    • Free Trials & Downloads
    • Splunk Community
    • Splunk Answers
    • SPL 2 Reference
    • Splunk Lantern

    Support

    • AppDynamics Support
    • Cisco Support
    • Product Security Advisories
    • Splunk Support
    • System Status
Splunk Enterprise
  • Search
    • Federated Search
      • Welcome to Splunk Federated Search
        • Overview of the federated search options for the Splunk platform
      • Run federated searches across other Splunk deployments
        • About Federated Search for Splunk
          • Components of a typical federated search setup
          • How Federated Search for Splunk works
          • Kinds of federated searches you can set up
          • About the standard and transparent modes
          • About Federated Search for Splunk and Splunk security and IT products
          • Set up Federated Search for Splunk between Splunk platform deployments
        • Migrate from hybrid search to Federated Search for Splunk
          • Comparing hybrid search and Federated Search for Splunk
          • Transparent or standard mode?
          • Move to federated search
        • Service accounts and security for Federated Search for Splunk
          • Security models for Federated Search for Splunk
          • Step one: Create a service account role on the remote deployment
          • Step two: Create a new service account user on the remote deployment and assign the role to it
          • About HTTPS with TLS 1.2 encryption for federated search
        • Set the app context for standard mode federated providers
          • Benefits of setting an app context
          • Find installed apps and their application short names
          • Create standard mode federated providers that have the same host name but different app contexts
          • Duplicate knowledge objects on local and remote search heads
        • Define a Splunk platform federated provider
          • Prerequisites
          • Steps
          • Configure the IP allow list
          • Troubleshoot a federated provider connection
          • About creating multiple federated provider definitions for the same host name and port
          • Next steps for a standard mode federated provider
          • Next step for a transparent mode federated provider
        • Map a federated index to a remote Splunk dataset
          • Specifying remote datasets
          • Ensure federated index replication to search head cluster members in your local Splunk Enterprise deployment
          • Prerequisites for federated index creation
          • Steps
          • Give your users access to federated indexes
          • Reference federated indexes in federated searches
        • Give your users role-based access control of federated indexes
        • Configure role-based access and search targeting for transparent mode federated providers
          • Override the default provider for a role
          • Target search routing using the splunk_federated_provider predicate
          • Examples
        • Run federated searches over remote Splunk platform deployments
          • General requirements for federated search
          • Search over a standard mode federated provider
            • SPL commands that run on the federated search head in standard mode
            • Standard mode federated search examples
            • Support for custom search commands
          • Search over a transparent mode federated provider
        • Manage knowledge objects for standard mode federated providers
          • Administer knowledge object definitions for standard mode federated providers
          • Use SPL commands with knowledge objects
          • Run standard mode federated searches using event types and tags
          • Run standard mode federated searches over lookups
          • Help with knowledge objects
        • Troubleshoot federated searches
        • Turn off transparent mode
          • Requirements
          • Authentication and authorization
          • Get current state of transparent mode search
          • Turn transparent mode search on or off
Splunk Enterprise › Search › Federated Search › Run federated searches across other Splunk deployments › Define a Splunk platform federated provider › Next step for a transparent mode federated provider

Next step for a transparent mode federated provider

After you define a transparent mode federated provider, you are ready to run federated searches. See Run federated searches over remote Splunk platform deployments.

Share this page
  • LinkedIn
  • X
  • Facebook
  • Email
Share feedback about this page
Previous Next steps for a standard mode federated provider Next Map a federated index to a remote Splunk dataset
logo
©2005-2026 Splunk Inc. All rights reserved.
Legal Privacy Website Terms of Use