One of several types of Splunk Enterprise instances. Each component handles one or more Splunk Enterprise roles, such as data input or indexing.

There are several types of Splunk Enterprise components. They fall into two broad categories:

  • Processing components. These components handle the data.
  • Management components. These components support the activities of the processing components.

In a distributed environment, you typically allocate the segments of the data pipeline to different processing components. These are the available processing component types:

Management components include:

For more information

In the Distributed Deployment Manual: