Splunk Components Architecture
Splunk Components Architecture
What is Splunk?
• Indexer
• Search head
• Deployment Server
• Cluster Master
• Forwarders
• Load Balancer
3
Indexer:
Search head:
Search head is a Splunk instance and it is a web interface
which is used to view the indexed
logs.
Cluster Master
Cluster Master is the Component which is used to replicate
whether the replication is happening between both indexer or
not.
License Master
It is the components which manager the License of the Splunk
enterpriser.
Deployment Master
It is the Server which manager the configuration on the client, Here
we can create app or rule that we used to pull the data from client.
Forwarder
Three types: Universal, Heavy and Stream forwarders.
8
Components distribution count
9
Port Numbers:
10
THANK YOU ! ! !
Confidentiality Notice
Co nfide ntiality No tic e
This file is private and may contain confidential
confidential and
and proprietary
proprietary information.
information. IfIf you
youhave
havereceived
receivedthis
thisfile
fileininerror,
error,please
pleasenotify
notifyus
usand
andremove
remove
it from your system and note that you must not not copy,
copy, distribute or take any
any action
action in in reliance
reliance on
on it.
it. Any
Any unauthorized
unauthorized use use or
or disclosure
disclosureof
ofthe
the
contents of this file is not permitted and
and may
may be
be unlawful.
unlawful. AstraZeneca
AstraZeneca PLC,
PLC, 11 Francis
Francis Crick
Crick Avenue,
Avenue, Cambridge
Cambridge Biomedical
Biomedical Campus,
Campus,
Cambridge, CB2 0AA, UK, T: T: +44(0)203
+44(0)203 749 5000, www.astrazeneca.com
11
10