- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Folks,
Please note that I am new to splunk,
I have a question what is the difference between full stack splunk and splunk enterprise
Would be appreciate your kind support you
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi gcusello,
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi gcusello,
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

It's hard to say what you mean by "full stack".
Splunk as a company has many different products/services. Typically when talking about "Splunk" as a product it's implied that we're talking about environment of Splunk Enterprise or Splunk Free (which is the same Splunk Enterprise binary but with a limited Splunk Free license applied) instance(s) and Splunk Universal Forwarders
Splunk Enterprise can be configured, depending on the needed role, as indexer, search-head, heavy forwarder, deployment server, shc deployer, cluster manager. But these are all instances of Splunk Enterprise servers.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Shakeer_Spl,
Splunk on premise has two main products (there are many others but for this scope two products):
- Splunk Enterprise:
- Splunk Universal Forwarder.
The second is a light agent that can be used only to input data and is usually installed on the target servers.
The second is a full stack version of the product that is usually installed on one or more dedicated servers, it can be used for all roles except agent: Indexer, Search Head, Heavy Forwarder, Master Node, License master, Deployer.
What is your requirement?
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Shakeer_Spl,
Splunk sells it's main solution in two ways:
- Splunk Cloud,
- Splunk Enterprise.
Splunk Enterprise is the on-premise version of Splunk Platform, differentiated by Splunk Cloud.
Splunk Enterprise can have many roles, but it's used always the same software version with the only exception of Splunk Universal Forwarder.
When you speak of full stack Splunk, probably you want to differentiate Splunk Heavy Forwarder from Splunk Universal Forwarder that are two different products and distributions:
- Splunk Universal Forwarder is an agent: a light versione of Splunk (different than Splunk Enterprise), without GUI, used only to ingest logs.
- Splunk Heavy Forwarder is a full stack Splunk Enterprise version of the product, where some features (e.g. indexing) aren't used because the scope of this role is take logs and forward them to Indexers.
Ciao.
Giuseppe
