Hi @informations4, in my opinion, in general, you should have: an Indexer Cluster with two Indexers and a Master Node, eventually (better!) a Search Head Cluster, with three Search Heads and a Deployer, only for lab, you could put the Deployer on the same server of Master Node, if you don't want a Search Head Cluster, you can use one Search Head, a Deployment Server, only for lab, you could put it on the same server of Master Node, une or two Universal Forwarders (possibly one Linux and one Windows), then you should configure one of the servers to send syslogs to the Linux Universal Forwarder. I configured my lab with six VMs and I used my laptop as client to manage using the DS. Ciao. Giuseppe
... View more