Splunk® Industrial Asset Intelligence (Legacy)

Install and Upgrade Splunk Industrial Asset Intelligence

Acrobat logo Download manual as PDF


Splunk Industrial Asset Intelligence reached its End of Sale on February 24, 2020.
Acrobat logo Download topic as PDF

Deployment planning for Splunk Industrial Asset Intelligence

You can deploy Splunk IAI in a single instance deployment or a distributed search deployment. Splunk IAI is not available in Splunk Cloud. Before you deploy Splunk IAI, familiarize yourself with the components of a Splunk platform deployment. See Components of a Splunk Enterprise deployment in the Splunk Enterprise Capacity Planning Manual.

Single-instance deployment

For a simple and small deployment, install Splunk IAI on a single Splunk Enterprise instance. A single instance functions as both a search head and an indexer. Do not install other apps or add-ons to the single-instance deployment unless instructed by the Splunk IAI documentation, Splunk Support, or Splunk Professional Services.

Use forwarders to collect your data and send it to the single instance for parsing, storing, and searching.

You can use a single-instance deployment for a lab or test environment or a small production system with fewer than 10 users.

To learn about the reference hardware specifications for a Splunk Enterprise single-instance deployment, see Reference host specification for single-instance deployments.

Distributed search deployments

For a standard or large-scale deployment, install Splunk IAI on a distributed search deployment of Splunk Enterprise.

Search heads

In a distributed search deployment, install Splunk IAI on a dedicated search head or search head cluster. Do not install other apps or add-ons to the same search head or search head cluster unless instructed by the documentation, Splunk Support, or Splunk Professional Services.

Indexers

Improve search performance by using an indexer cluster and distributing the workload of searching data across multiple nodes. Using multiple indexers or an indexer cluster allows both the data collected by the forwarders and the workload of processing the data to be distributed across the indexers.

In a large Splunk Industrial Asset Intelligence deployment, indexers must be able to process thousands of queries per minute. For help determining your indexer requirements, consult your Splunk Professional Services or Support representative.

Forwarders

Use forwarders to ingest and send data to indexers.

Last modified on 23 January, 2019
PREVIOUS
Installation overview for Splunk Industrial Asset Intelligence
  NEXT
Capacity planning for Splunk Industrial Asset Intelligence

This documentation applies to the following versions of Splunk® Industrial Asset Intelligence (Legacy): 1.2.1, 1.2.2, 1.3.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters