Splunk® Enterprise

Distributed Deployment Manual

Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Implement a distributed deployment

This topic provides a high-level framework for implementing a basic multi-tiered distributed environment such as this:

Horizontal scaling new2 60.png

To implement this sort of distributed environment, you need to install and configure three types of components:

  • Indexers
  • Forwarders (typically, universal forwarders)
  • Search head(s)

Install and configure the indexers

By default, all full Splunk Enterprise instances serve as indexers. For horizontal scaling, you can install multiple indexers on separate machines.

To learn how to install a Splunk Enterprise instance, read the Installation Manual.

Once you've installed the indexers, see the Managing Indexers and Clusters of Indexers manual for information on configuring each indexer to meet the needs of your specific deployment.

To prepare your indexers to receive data from forwarders, see "Enable a receiver" in the Forwarding Data manual. In addition, if the indexers will be consuming some data inputs directly, rather than through forwarders, see the Getting Data In manual for information on configuring data inputs. The diagram in this topic shows two direct inputs, one from a firewall and another from a data router.

If data availability, data fidelity, and data recovery are key issues for your deployment, you should consider deploying an indexer cluster, rather than a series of individual indexers. For further information, see "About indexer clusters and index replication" in the Managing Indexers and Clusters of Indexers manual.

Install and configure the forwarders

A typical distributed deployment has a large number of forwarders feeding data to a few indexers. For most forwarding purposes, the universal forwarder is the best choice. The universal forwarder is a separate downloadable from the full Splunk Enterprise instance.

To learn how to install and configure forwarders, read the Forwarding Data manual.

Then read the Getting Data In manual for information on configuring each forwarder's data inputs.

Install and configure the search heads

You can install one or more search heads to handle your distributed search needs. Search heads are full Splunk Enterprise instances that have been specially configured to managed searches across a set of indexers. Users run searches by connecting to the search head's Splunk Web.

To learn how to configure a search head, read the Distributed Search manual.

Other deployment tasks

You need to configure Splunk Enterprise licensing by designating a license master. See the chapter Configure Splunk Enterprise licenses in the Admin Manual for more information.

You can use the Splunk Enterprise deployment server to simplify the job of updating the deployment components. For details on how to configure a deployment server, see the Updating Splunk Enterprise Instances manual.

Last modified on 25 February, 2015
Components and roles
Forwarding data

This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters