<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk architect for indexers and searches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-architect-for-indexers-and-searches/m-p/104193#M26980</link>
    <description>&lt;P&gt;Currently I am using splunk like this&lt;BR /&gt;
one splunk server(machine) that having search head, indexes(in one splunk server more indexers)&lt;/P&gt;

&lt;P&gt;i saw the doc &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview&lt;/A&gt;&lt;BR /&gt;
I did not get in this doc, more search heads are in diffrent servers(more than one machine) and indexers are in diffrent servers (more than one machine) or all are in same server(machine) and also about the forwarders pushing data.&lt;/P&gt;

&lt;P&gt;can anyone please explain me this architecture ? and also if you have any better architect then please let me know.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Mar 2012 13:38:47 GMT</pubDate>
    <dc:creator>kml_uvce</dc:creator>
    <dc:date>2012-03-29T13:38:47Z</dc:date>
    <item>
      <title>splunk architect for indexers and searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-architect-for-indexers-and-searches/m-p/104193#M26980</link>
      <description>&lt;P&gt;Currently I am using splunk like this&lt;BR /&gt;
one splunk server(machine) that having search head, indexes(in one splunk server more indexers)&lt;/P&gt;

&lt;P&gt;i saw the doc &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview&lt;/A&gt;&lt;BR /&gt;
I did not get in this doc, more search heads are in diffrent servers(more than one machine) and indexers are in diffrent servers (more than one machine) or all are in same server(machine) and also about the forwarders pushing data.&lt;/P&gt;

&lt;P&gt;can anyone please explain me this architecture ? and also if you have any better architect then please let me know.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2012 13:38:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-architect-for-indexers-and-searches/m-p/104193#M26980</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2012-03-29T13:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: splunk architect for indexers and searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-architect-for-indexers-and-searches/m-p/104194#M26981</link>
      <description>&lt;P&gt;These links will probably be helpful to you in understanding the basic Splunk architecture for a single server.  Essentially you have the Search Head, Indexer, Forwarder all on the same server.  We have the capabilities to distribute those components to multiple servers in order to scale our environment.&lt;/P&gt;

&lt;P&gt;This explains the different components which you have all on one server.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Installation/ComponentsofaSplunkdeployment"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Installation/ComponentsofaSplunkdeployment&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This explains a more logical representation of the inner functions of a Splunk server. Diagram towards the bottom of the page.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.1/Installation/Splunksarchitectureandwhatgetsinstalled"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.1/Installation/Splunksarchitectureandwhatgetsinstalled&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2012 14:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-architect-for-indexers-and-searches/m-p/104194#M26981</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-03-29T14:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: splunk architect for indexers and searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-architect-for-indexers-and-searches/m-p/104195#M26982</link>
      <description>&lt;P&gt;do you mean that we can also do diffrent search heads in diffrent servers and diffrent indexers in diffrent servers ?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2012 22:40:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-architect-for-indexers-and-searches/m-p/104195#M26982</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2012-03-29T22:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: splunk architect for indexers and searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-architect-for-indexers-and-searches/m-p/104196#M26983</link>
      <description>&lt;P&gt;Not sure what you mean.  You are able to have multiple indexers and search heads on multiple servers in order to scale your environment and improve performance for processing increased amounts of data.  A typical indexer is good for about 100 GB of data per day, a typical search head running on an 8 core server will allow for 8 concurrent searches.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2012 17:22:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-architect-for-indexers-and-searches/m-p/104196#M26983</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-04-03T17:22:35Z</dc:date>
    </item>
  </channel>
</rss>

