Documentation: 3.2.2
Print Version Contents
This page last updated: 04/14/08 12:04pm

Components of a Splunk deployment

Splunk is simple to deploy by design. By using a single software component and easy to understand configurations, Splunk can coexist with existing infrastructure or be deployed as a universal platform for accessing IT data.

Splunk can start up and run in several different modes, each of which can serve as a component to meet your deployment requirements. This section covers these potential components:

Indexer

http://www.splunk.com/assets/doc-images/DeployArchComponents/indexer.png

In this mode, indexers, or index servers, provide indexing capability for local and remote data and host the primary Splunk datastore, as well as Splunk Web.

Forwarder

http://www.splunk.com/assets/doc-images/DeployArchComponents/forwarder.png

Forwarders use the same Splunk software package but do not store indexed data locally. All indexed data is forwarded to remote index servers. To reduce operational footprint, Splunk Web is not used. Refer to the documentation on setting up a Splunk instance as a forwarder.

Deployment server

http://www.splunk.com/assets/doc-images/DeployArchComponents/deploymentserver.png

Both indexers and forwarders can also act as deployment servers. A deployment server distributes configuration information to running instances of Splunk via a push mechanism which is enabled through configuration. Refer to the documentation on setting up a Splunk instance as a deployment server.

Previous: About the Splunk Deployment Guide    |    Next: Data inputs

Comments

No comments have been submitted.

Log in to comment.