Splunk® Enterprise

Admin Manual

Acrobat logo Download manual as PDF


Splunk Enterprise version 7.1 is no longer supported as of October 31, 2020. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Splunk platform administration: the big picture

The Admin Manual provides information about the initial administration tasks as well as information about the different methods you can use to administer your Splunk software. For a more specific overview of what you can do with the Admin Manual, see How to use this manual.

Below are administration tasks you might want to do after initial configuration and where to go to learn more.

Task: Look here:
Perform backups Back up configuration information
Back up indexed data
Set a retirement and archiving policy
Define alerts The Alerting Manual
Manage search jobs Manage search jobs

For more administration help, see the manuals described below.

Install and upgrade Splunk Enterprise

The Installation Manual describes how to install and upgrade Splunk Enterprise. For information on specific tasks, start here.

Task: Look here:
Understand installation requirements Plan your installation
Estimate hardware capacity needs Estimate hardware requirements
Install Splunk Install Splunk Enterprise on Windows
Install Splunk Enterprise on Unix, Linux, or MacOS
Upgrade Splunk Enterprise Upgrade from an earlier version

Get data in

Getting Data In is the place to go for information about data inputs: how to consume data from external sources and how to enhance the value of your data.

Task: Look here:
Learn how to consume external data How to get data into Splunk
Configure file and directory inputs Get data from files and directories
Configure network inputs Get network events
Configure Windows inputs Get Windows data
Configure miscellaneous inputs Other ways to get stuff in
Enhance the value of your data Configure event processing
Configure timestamps
Configure indexed field extraction
Configure host values
Configure source types
Manage event segmentation
Use lookups and workflow actions
See how your data will look after indexing Preview your data
Improve the process Improve the data input process

Manage indexes and indexers

Managing Indexers and Clusters tells you how to configure indexes. It also explains how to manage the components that maintain indexes: indexers and clusters of indexers.

Task: Look here:
Learn about indexing Indexing overview
Manage indexes Manage indexes
Manage index storage Manage index storage
Back up indexes Back up indexed data
Archive indexes Set a retirement and archiving policy
Learn about clusters and index replication About clusters and index replication
Deploy clusters Deploy clusters
Configure clusters Configure clusters
Manage clusters Manage clusters
Learn about cluster architecture How clusters work

Scale Splunk platform deployments

The Distributed Deployment Manual describes how to distribute Splunk platform functionality across multiple components, such as forwarders, indexers, and search heads. Associated manuals cover distributed components in detail:

Task: Look here:
Learn about distributed Splunk platform deployments Scale deployments
Perform capacity planning for Splunk platform deployments Estimate hardware requirements
Learn how to forward data Forward data
Distribute searches across multiple indexers Search across multiple indexers
Update the deployment Deploy configuration updates across your environment

Secure Splunk Enterprise

Securing Splunk tells you how to secure your Splunk Enterprise deployment.

Task: Look here:
Authenticate users and edit roles User and role-based access control
Secure data with SSL Secure authentication and encryption
Audit Splunk software Audit system activity
Use Single Sign-On (SSO) with Splunk software Configure Single Sign-on
Use Splunk software with LDAP Set up user authentication with LDAP

Troubleshoot Splunk software

The Troubleshooting Manual provides overall guidance on Splunk platform troubleshooting. In addition, topics in other manuals provide troubleshooting information on specific issues.

Task: Look here:
Learn about Splunk platform troubleshooting tools First steps
Learn about Splunk log files Splunk log files
Work with Splunk support Contact Splunk support
Resolve common problems Some common scenarios

References and other information

The Splunk documentation includes several useful references, as well as some other sources of information that might be of use to the Splunk software administrator.

Reference: Look here:
Configuration file reference Configuration file reference in the Admin Manual
REST API reference REST API Reference Manual
CLI help Available through installed instances of Splunk Enterprise. For details on how to invoke it, read Get help with the CLI in the Admin Manual.
Release information Release Notes
Information on managing Splunk platform knowledge objects Knowledge Manager Manual
Last modified on 14 October, 2020
PREVIOUS
How to use this manual
  NEXT
Other manuals for the Splunk platform administrator

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters