A single running installation of Splunk Enterprise.

In single-instance deployments, a single instance of Splunk Enterprise handles all data processing functions, including data input, indexing, and search management.

In distributed deployments, processes are distributed across multiple Splunk Enterprise instances running on multiple machines. Each instance performs a specialized role, such as data input, indexing, search management, or various housekeeping functions. Specialized Splunk Enterprise instances are called components.

