<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is Splunk Search Head ? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-Splunk-Search-Head/m-p/689613#M28244</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248866"&gt;@thevikramyadav&lt;/a&gt;&amp;nbsp;... all the best for your splunk learning..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;remember these 3 components...&amp;nbsp;&lt;BR /&gt;1) Splunk Universal forwarder collects the logs and send it to Splunk indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Splunk indexer, indexes(ingests) the logs(it reads the logs, word by word, and write it down to flat files for searching)&lt;/P&gt;&lt;P&gt;3) Splunk Search head - its the webserver which provides the Splunk GUI login page, it reads the search requests from the users and send it to indexer. and collects the results from indexer, consolidates, reports it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From Splunk documentations:&lt;/P&gt;&lt;P&gt;In a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Distributedsearch" href="https://docs.splunk.com/Splexicon:Distributedsearch" target="_blank"&gt;distributed search&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;environment, a Splunk Enterprise instance that handles&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Searchmanagement" href="https://docs.splunk.com/Splexicon:Searchmanagement" target="_blank"&gt;search management&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;functions, directing search requests to a set of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Searchpeer" href="https://docs.splunk.com/Splexicon:Searchpeer" target="_blank"&gt;search peers&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and then merging the results back to the user.&lt;/P&gt;&lt;P&gt;A Splunk Enterprise instance can function as both a search head and a search peer. A search head that performs only searching, and not any indexing, is referred to as a dedicated search head.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Searchheadcluster" href="https://docs.splunk.com/Splexicon:Searchheadcluster" target="_blank"&gt;Search head clusters&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;are groups of search heads that coordinate their activities.&lt;/P&gt;&lt;P&gt;Search heads are also required components of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Indexercluster" href="https://docs.splunk.com/Splexicon:Indexercluster" target="_blank"&gt;indexer clusters.&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2024 21:03:32 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2024-06-04T21:03:32Z</dc:date>
    <item>
      <title>What is Splunk Search Head ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-Splunk-Search-Head/m-p/689612#M28243</link>
      <description>&lt;P&gt;Can someone help me to get more idea on Splunk Search Head and how it work's ?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 20:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-Splunk-Search-Head/m-p/689612#M28243</guid>
      <dc:creator>thevikramyadav</dc:creator>
      <dc:date>2024-06-04T20:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: What is Splunk Search Head ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-is-Splunk-Search-Head/m-p/689613#M28244</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/248866"&gt;@thevikramyadav&lt;/a&gt;&amp;nbsp;... all the best for your splunk learning..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;remember these 3 components...&amp;nbsp;&lt;BR /&gt;1) Splunk Universal forwarder collects the logs and send it to Splunk indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Splunk indexer, indexes(ingests) the logs(it reads the logs, word by word, and write it down to flat files for searching)&lt;/P&gt;&lt;P&gt;3) Splunk Search head - its the webserver which provides the Splunk GUI login page, it reads the search requests from the users and send it to indexer. and collects the results from indexer, consolidates, reports it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From Splunk documentations:&lt;/P&gt;&lt;P&gt;In a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Distributedsearch" href="https://docs.splunk.com/Splexicon:Distributedsearch" target="_blank"&gt;distributed search&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;environment, a Splunk Enterprise instance that handles&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Searchmanagement" href="https://docs.splunk.com/Splexicon:Searchmanagement" target="_blank"&gt;search management&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;functions, directing search requests to a set of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Searchpeer" href="https://docs.splunk.com/Splexicon:Searchpeer" target="_blank"&gt;search peers&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and then merging the results back to the user.&lt;/P&gt;&lt;P&gt;A Splunk Enterprise instance can function as both a search head and a search peer. A search head that performs only searching, and not any indexing, is referred to as a dedicated search head.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Searchheadcluster" href="https://docs.splunk.com/Splexicon:Searchheadcluster" target="_blank"&gt;Search head clusters&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;are groups of search heads that coordinate their activities.&lt;/P&gt;&lt;P&gt;Search heads are also required components of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Indexercluster" href="https://docs.splunk.com/Splexicon:Indexercluster" target="_blank"&gt;indexer clusters.&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 21:03:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-is-Splunk-Search-Head/m-p/689613#M28244</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-06-04T21:03:32Z</dc:date>
    </item>
  </channel>
</rss>

