Deployment Architecture

What is Search Head? Can it be seen in the UI?

gokikrishnan198
New Member

In the Splunk Architeture, it is known that Splunk has major 3 components.

1. Forwarder - Instance installed at the log collection devices
2. Indexer - Virtual Instance installed with SPLUNK for parsing the collected logs
3. Search Head - Not very clear about where do we have it. Can somebody explain in non-technical words, what is a Search Head and Where can we find it?

Tags (1)
0 Karma

493669
Super Champion

Search Head is the one which we use for searching the logs from indexer...
Basically the Full Splunk instance can act as Heavy Forwarder/Indexer/Search head...its just a configuration due to which it acts different.
https://answers.splunk.com/answers/1324/what-is-a-search-head.html

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...