Deployment Architecture

How to design Splunk System?

axl88
Communicator

Hi, we are planning to deploy splunk for our application servers. I was wondering when we think about different environments(production,development etc..), what is the most feasible way of start using splunk?

Writing Splunk application? how hard is it? where to start?

0 Karma
1 Solution

piebob
Splunk Employee
Splunk Employee

this is an extremely high-level and general question. there are a lot of things you need to think about first, including: what do you want to accomplish with Splunk? what sort of data will you be indexing? what do you want to learn from it? how many users will you have? what is your budget?

if you're planning to deploy Splunk at your enterprise, you should work with your sales team (which will include a Sales Engineer) to help you plan your deployment.

a good place to get information is the Splunk documentation. i recommend starting with the tutorial to get a high-level idea of what's possible with Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

here is information about creating dashboards and views (which is part of developing apps) for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Viz/Aboutthismanual

here is some information about common deployment architectures for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Architectureoverview
the rest of the Distributed Deployment Manual will also provide good info about what's possible.

View solution in original post

piebob
Splunk Employee
Splunk Employee

this is an extremely high-level and general question. there are a lot of things you need to think about first, including: what do you want to accomplish with Splunk? what sort of data will you be indexing? what do you want to learn from it? how many users will you have? what is your budget?

if you're planning to deploy Splunk at your enterprise, you should work with your sales team (which will include a Sales Engineer) to help you plan your deployment.

a good place to get information is the Splunk documentation. i recommend starting with the tutorial to get a high-level idea of what's possible with Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

here is information about creating dashboards and views (which is part of developing apps) for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Viz/Aboutthismanual

here is some information about common deployment architectures for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Architectureoverview
the rest of the Distributed Deployment Manual will also provide good info about what's possible.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...