Deployment Architecture

How to design Splunk System?

axl88
Communicator

Hi, we are planning to deploy splunk for our application servers. I was wondering when we think about different environments(production,development etc..), what is the most feasible way of start using splunk?

Writing Splunk application? how hard is it? where to start?

0 Karma
1 Solution

piebob
Splunk Employee
Splunk Employee

this is an extremely high-level and general question. there are a lot of things you need to think about first, including: what do you want to accomplish with Splunk? what sort of data will you be indexing? what do you want to learn from it? how many users will you have? what is your budget?

if you're planning to deploy Splunk at your enterprise, you should work with your sales team (which will include a Sales Engineer) to help you plan your deployment.

a good place to get information is the Splunk documentation. i recommend starting with the tutorial to get a high-level idea of what's possible with Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

here is information about creating dashboards and views (which is part of developing apps) for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Viz/Aboutthismanual

here is some information about common deployment architectures for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Architectureoverview
the rest of the Distributed Deployment Manual will also provide good info about what's possible.

View solution in original post

piebob
Splunk Employee
Splunk Employee

this is an extremely high-level and general question. there are a lot of things you need to think about first, including: what do you want to accomplish with Splunk? what sort of data will you be indexing? what do you want to learn from it? how many users will you have? what is your budget?

if you're planning to deploy Splunk at your enterprise, you should work with your sales team (which will include a Sales Engineer) to help you plan your deployment.

a good place to get information is the Splunk documentation. i recommend starting with the tutorial to get a high-level idea of what's possible with Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

here is information about creating dashboards and views (which is part of developing apps) for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Viz/Aboutthismanual

here is some information about common deployment architectures for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Architectureoverview
the rest of the Distributed Deployment Manual will also provide good info about what's possible.

Get Updates on the Splunk Community!

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...

Enterprise Security Content Update (ESCU) | New Releases

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...