Article
Splunk Enterprise: From Data Ingestion to Distributed Search
Explore forwarders, indexers, search head clusters and the deployer through Cisco’s published tiered architecture.

Turn logs, events and operational data into actionable insights. Establish shared visibility for security analytics, incident investigations and service performance with Splunk.

Turn logs, events and operational data into actionable insights. Establish shared visibility for security analytics, incident investigations and service performance with Splunk.
Zoom in to explore the roles and connections in the source figure.
Select a node to read its role. Drag to pan or use the buttons to zoom.
Search, indexing and forwarding tiers match the source. Ellipses represent further members; two icons do not mean a two-member search head cluster. Braces indicate tier/group relationships, not cables.