Deployment Architecture

How to design Splunk System?

axl88
Communicator

Hi, we are planning to deploy splunk for our application servers. I was wondering when we think about different environments(production,development etc..), what is the most feasible way of start using splunk?

Writing Splunk application? how hard is it? where to start?

0 Karma
1 Solution

piebob
Splunk Employee
Splunk Employee

this is an extremely high-level and general question. there are a lot of things you need to think about first, including: what do you want to accomplish with Splunk? what sort of data will you be indexing? what do you want to learn from it? how many users will you have? what is your budget?

if you're planning to deploy Splunk at your enterprise, you should work with your sales team (which will include a Sales Engineer) to help you plan your deployment.

a good place to get information is the Splunk documentation. i recommend starting with the tutorial to get a high-level idea of what's possible with Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

here is information about creating dashboards and views (which is part of developing apps) for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Viz/Aboutthismanual

here is some information about common deployment architectures for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Architectureoverview
the rest of the Distributed Deployment Manual will also provide good info about what's possible.

View solution in original post

piebob
Splunk Employee
Splunk Employee

this is an extremely high-level and general question. there are a lot of things you need to think about first, including: what do you want to accomplish with Splunk? what sort of data will you be indexing? what do you want to learn from it? how many users will you have? what is your budget?

if you're planning to deploy Splunk at your enterprise, you should work with your sales team (which will include a Sales Engineer) to help you plan your deployment.

a good place to get information is the Splunk documentation. i recommend starting with the tutorial to get a high-level idea of what's possible with Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

here is information about creating dashboards and views (which is part of developing apps) for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Viz/Aboutthismanual

here is some information about common deployment architectures for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Architectureoverview
the rest of the Distributed Deployment Manual will also provide good info about what's possible.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...