Hi @Mad2, about Universal Forwarder, as @richgalloway said, you don't need it if you have a full Splunk instance, even if it's a lab installation. About the opportunity to have Search Head, Indexer...
See more...
Hi @Mad2, about Universal Forwarder, as @richgalloway said, you don't need it if you have a full Splunk instance, even if it's a lab installation. About the opportunity to have Search Head, Indexer and Monitoring Console on the same server, it's possible if you have a stand alone Splunk Server , and to have it, you don't need to do nothing, only install Splunk. If instead you have a distributed architecture, with more SHs and/or more indexers, it isn't possible: you must have dedicated systems for SHs and different dedicated systems for IDXs. Monitoring Console could share the system with other roles, but not SHs, IDXs and Deployment Server (if you have to manage more than 50 clients). Ciao. Giuseppe