Deployment Architecture

Local log storage

ebdavison
New Member

My only previous experience with Splunk was in the every beginning and I have been asked to look at this again. In the beginning all logs were sent up to splunk servers for storage and analysis. I cannot tell definitively whether this is still the case.

If I download either the free or the enterprise version, are the logs stored locally ONLY? This is very important due to the nature of our logs.

Is there any information that is forwarded to splunk servers?

Tags (1)
0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

When you run Splunk (either free or enterprise), nodes are divided up into two classes - indexers and forwarders. Forwarders forward log data to indexers who store it on their locally attached disks. (A bit of an oversimplification here, because forwarders can index locally before forwarding and so on, but for purpose of answering your question it's close enough)

At least with current versions of Splunk (4.0 and above - I have no personal experience with prior versions), neither forwarders nor indexers send your log data to servers outside of your control. (That is, unless you configure them explicitly to do so). Your data is NEVER sent to a Splunk.com repository in the sky.

View solution in original post

LCM
Contributor

Not sure what exactly you mean - maybe you re-describe it more clearly! (like, what is your environment look like at the moment, where are your logs right now, and what do you want to do with it -> with splunk)

Just as much: You either can store your data "locally" or send it further to another "device" or both!

You also may check out: http://www.splunk.com/base/Documentation/latest/Admin/Whatsinthismanual

dwaddle
SplunkTrust
SplunkTrust

When you run Splunk (either free or enterprise), nodes are divided up into two classes - indexers and forwarders. Forwarders forward log data to indexers who store it on their locally attached disks. (A bit of an oversimplification here, because forwarders can index locally before forwarding and so on, but for purpose of answering your question it's close enough)

At least with current versions of Splunk (4.0 and above - I have no personal experience with prior versions), neither forwarders nor indexers send your log data to servers outside of your control. (That is, unless you configure them explicitly to do so). Your data is NEVER sent to a Splunk.com repository in the sky.

ebdavison
New Member

Thanks, that helps to clarify the storage for me. When Splunk was first released all that was available was a forwarder for download. Splunk had the only indexers. Now I can see this is now offered locally for both services.

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...