component

noun

The various types of Splunk instances. Each component is dedicated to one or more Splunk roles, such as data input and indexing. In a distributed environment, you typically allocate the various segments of the data pipeline to different components.

These are the Splunk component types available for use in a distributed environment:

For more information

In the Distributed Deployment manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time