Splunk

Splunk

Turn logs, events and operational data into actionable insights. Establish shared visibility for security analytics, incident investigations and service performance with Splunk.

SplunkSecurity and Observability

Partnership

Turn logs, events and operational data into actionable insights. Establish shared visibility for security analytics, incident investigations and service performance with Splunk.

CISCO · Figure 6

Splunk: tiered reference architecture

Zoom in to explore the roles and connections in the source figure.

Search Head Cluster · Cluster membersSearch Peers (Indexers)ForwardersUsersUser group shown above the search head cluster in the source.Search headSearch head cluster member shown in the source; a search-tier role.Search headOther illustrated member; the ellipsis represents additional members.DeployerConnected to the search head cluster by the source's single arrow, representing search-head app deployment.Indexer / Search peerIndexing-tier member that receives, indexes and stores forwarded data.Indexer / Search peerSecond illustrated indexer icon; further indexers are represented by an ellipsis.ForwarderForwarding role that consumes source data and sends it to indexers. This figure does not draw physical cabling.ForwarderSecond forwarding icon in the source; an ellipsis represents further forwarders.………Search management · Indexing · Data input
  • Application deployment relationship
Explore the diagram

Select a node to read its role. Drag to pan or use the buttons to zoom.

Search, indexing and forwarding tiers match the source. Ellipses represent further members; two icons do not mean a two-member search head cluster. Braces indicate tier/group relationships, not cables.