A customer wants to implement LDAP because managing local Splunk users is becoming too much of an overhead. What configuration details are needed from the customer to implement LDAP authentication?
In a subsearch, the result of the inner search is used as a filter for what other component of subsearch?
How does the Search Job Inspector distinguish commands that execute on indexers from commands that execute on search heads?
A customer has 30 indexers in an indexer cluster configuration and two search heads. They are working on writing SPL search for a particular use-case, but are concerned that it takes too long to run for short time durations.
How can the Search Job Inspector capabilities be used to help validate and understand the customer concerns?