The volume of data from collecting log files from 50 Linux servers and 200 Windows servers will
require multiple indexers
Following best practices, which types of Splunk component instances are needed?
You may opt for - Indexers, search head, deployment server, license master, universal forwarder.
But you may also go for Indexers, search head, deployment server, license master, universal forwarder, heavy forwarder, adding an HF is better if you have lot of data and needs further parsing
Hi @nandhukiran37,
the roles of Splunk Servers, as you can easily think, depend on your requisites:
At the end of this description, my hint is to engage a Splunk Architect to design your Splunk architect and define the correct sizing for all the systems.
You can find some documentation at https://docs.splunk.com/Documentation/Splunk/8.0.6/Deploy/Manageyourdeployment
Ciao.
Giuseppe