Deployment Architecture

How to design Splunk System?

axl88
Communicator

Hi, we are planning to deploy splunk for our application servers. I was wondering when we think about different environments(production,development etc..), what is the most feasible way of start using splunk?

Writing Splunk application? how hard is it? where to start?

0 Karma
1 Solution

piebob
Splunk Employee
Splunk Employee

this is an extremely high-level and general question. there are a lot of things you need to think about first, including: what do you want to accomplish with Splunk? what sort of data will you be indexing? what do you want to learn from it? how many users will you have? what is your budget?

if you're planning to deploy Splunk at your enterprise, you should work with your sales team (which will include a Sales Engineer) to help you plan your deployment.

a good place to get information is the Splunk documentation. i recommend starting with the tutorial to get a high-level idea of what's possible with Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

here is information about creating dashboards and views (which is part of developing apps) for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Viz/Aboutthismanual

here is some information about common deployment architectures for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Architectureoverview
the rest of the Distributed Deployment Manual will also provide good info about what's possible.

View solution in original post

piebob
Splunk Employee
Splunk Employee

this is an extremely high-level and general question. there are a lot of things you need to think about first, including: what do you want to accomplish with Splunk? what sort of data will you be indexing? what do you want to learn from it? how many users will you have? what is your budget?

if you're planning to deploy Splunk at your enterprise, you should work with your sales team (which will include a Sales Engineer) to help you plan your deployment.

a good place to get information is the Splunk documentation. i recommend starting with the tutorial to get a high-level idea of what's possible with Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

here is information about creating dashboards and views (which is part of developing apps) for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Viz/Aboutthismanual

here is some information about common deployment architectures for Splunk:
http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Architectureoverview
the rest of the Distributed Deployment Manual will also provide good info about what's possible.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...