Splunk Search

Splunk Installation.

VijayA
Explorer

Hi,

I'm new to Splunk, trying to understand for Splunk we have 1 installation we need to customize it to work as Forwarder or Indexer or Search Head, So want to know which all files need to modify to work as forwarder or indexer.

Correct me if my understanding is wrong.

Please advise thanks.

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @VijayA,

A Splunk Enterprise installation can work as an Indexer, a Search or a Heavy Forwarder: the installation packet is always the same, and the role depends on the configuration.

What is the architecture you want to implement?

if you want a distributed architecture, you have to configure at least one Indexer and one Search Head, the difference is that the Indexer indexes logs and the Search Head is the user Front end.

Otherwise, you could have a Stand Alone server where the same server is the Indexer and the Search Head.

Instaed the Heavy Forwarder is used e.g. to pull logs from cloud or to receive syslogs.

Anyway, the server role depemds on your requirement: what are your requirements?

I hint to read the document https://www.splunk.com/pdfs/technical-briefs/splunk-validated-architectures.pdf that gives you an overview of the possible architectures, at the same time I hint to contact a Splunk partner to analyze your requiremts and design your architecture, It isn't a good idea to start without any knowledge about Splunk architectures and features..

Ciao.

Giuseppe

View solution in original post

VijayA
Explorer

Thank you for your inputs and document.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @VijayA,

A Splunk Enterprise installation can work as an Indexer, a Search or a Heavy Forwarder: the installation packet is always the same, and the role depends on the configuration.

What is the architecture you want to implement?

if you want a distributed architecture, you have to configure at least one Indexer and one Search Head, the difference is that the Indexer indexes logs and the Search Head is the user Front end.

Otherwise, you could have a Stand Alone server where the same server is the Indexer and the Search Head.

Instaed the Heavy Forwarder is used e.g. to pull logs from cloud or to receive syslogs.

Anyway, the server role depemds on your requirement: what are your requirements?

I hint to read the document https://www.splunk.com/pdfs/technical-briefs/splunk-validated-architectures.pdf that gives you an overview of the possible architectures, at the same time I hint to contact a Splunk partner to analyze your requiremts and design your architecture, It isn't a good idea to start without any knowledge about Splunk architectures and features..

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...