Deployment Architecture

Q1

mariamms
New Member

Explain Splunk Enterprise Event Collector, Processor and Console architecture.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mariamms ,

here you can find all the information you need about HEC:

at first https://www.splunk.com/en_us/pdfs/tech-brief/splunk-validated-architectures.pdf (page 28)

https://docs.splunk.com/Documentation/SplunkCloud/9.1.2312/Data/ShareHECData

https://www.youtube.com/watch?v=qROXrFGqWAU

In few words, you have to creare an HEC received creating a token that must be passed to the sender.

You can also have an intermediate Load Balancer for HA features, in this case, you must have the same token in all the receivers.

About Console, what do you mean?

HEC hasn't any console.

If your're speaking of the Cluster consoles, you have to search for Cluster Master (for Indexer Cluster) and SH Deployer (for Search Head Cluster).

You can find information at https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Aboutclusters and https://docs.splunk.com/Documentation/Splunk/9.2.0/DistSearch/AboutSHC

At least there's also a Monitorig Console and you can find information at https://docs.splunk.com/Documentation/Splunk/9.2.0/DMC/DMCoverview 

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OP is aparently looking for someone to produce an output useable as answer to a question in some course quiz. (Hence Q1).

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...