Introto Splunk
Introto Splunk
Splunk
Lecture #1
What is Splunk? By Wikipedia
Machine Data
accessible across organization
identify patterns
diagnose potential problems
provide intelligence
Why Splunk?
Machines produce great volumes of data
Central Repository
Data Access for Analytics
Structure and meaning of data
Visualization
Applications
Splunk Architecture
4 Major components
Search Head
Forwader
Indexer
Deployment Server
Splunk Architecture
Search Head
Indexing Tier
… x5
Forwarders or
Forwarding Tier
Data Sources