Splunk® App for Windows Infrastructure

Deploy and Use the Splunk App for Windows Infrastructure

Download manual as PDF

This documentation does not apply to the most recent version of MSApp. Click here for the latest version.
Download topic as PDF

What a Splunk App for Windows Infrastructure deployment looks like

This topic discusses the overall architecture of a Splunk App for Windows Infrastructure deployment.

Introduction

A Splunk App for Windows Infrastructure deployment consists of a Splunk Enterprise instance (that contains the index and runs Splunk Web, and that users access to view the app) and a number of universal forwarders--one for each Active Directory or Windows server you want to include in the deployment.

This setup procedure guides you through the install of nearly all components on one hosts. This means that:

  • The host will act as the indexer to receive incoming data from forwarders.
  • The host will act as a deployment server to manage forwarders and deploy apps and configurations.
  • The host will act as a search head to host the app and view the incoming data.

Only the universal forwarders in this deployment will be on different hosts. This helps reduce confusion on what components need to be installed where. Once you have an understanding of how the app and its components work, you can read the topic on how to scale the deployment for increased performance on larger environments.

Deployment diagram

The diagram below depicts an example Splunk App for Windows Infrastructure deployment.

Winfra 13 Setup Basic.png

Get started

The next page details the installation of the first piece of your Splunk App for Windows Infrastructure deployment: setting up the indexer that will act as the hub for the entire operation.

PREVIOUS
What data the Splunk App for Windows Infrastructure collects
  NEXT
How to deploy the Splunk App for Windows Infrastructure

This documentation applies to the following versions of Splunk® App for Windows Infrastructure: 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.5.0, 1.5.1


Comments

Very useful depiction of this app and its supported add-ons. I wish they all did this. Quite useful!

W199284
April 3, 2019

Hi @Martin and @Julieeball: Splunk App for Windows Infrastructure should not be installed on the indexer - you're correct. The diagram will be updated this week. Sorry for the delay in our response!

Abowman splunk, Splunker
December 17, 2018

No, I believe it should just be on the Search Head.

Julieeball
July 19, 2018

Hi Splunk Docs Team,
within the picture above, the splunk app for windows instracture should be installed on the indexer too, is that really correct?
Best Regards
Martin

NDsupport
May 29, 2018

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters