Introduction To Splunk
Introduction To Splunk
Introduction To Splunk
Index
Report & Data Log
Analyze Analytics
Search &
Reporting
Machine data
Monitor & Alert visualizations
Add Knowledge
Splunk components
Search Head
Indexer
Splunk
Enterprise Forwarder
Splunk Enterprise
Data Phases in splunk
Source
Sourcetype
Host
Index –
main(default)
Splunk Phases - Detailed
• Input phase – is handled at the source ( mostly forwarder)
The source data is opened & read, any configuration settings are applied.
• Parsing phase – handled by heavy forwarder or indexer(part of Splunk enterprise)
Data is broken down into a series of events and advanced operations like masking, selection can be done
• Indexing phase – The parsed data runs through the license meter before getting written to disk, prior to
compression.
Indexed data cannot be changed.
• Search phase – Taken care of by the search head (part of splunk enterprise)
Licensing
Source Parsing meter Indexing Searching
Universal
Fwd
Data Disk
Splunk Enterprise - Standalone
Splunk Enterprise
Splunk Deployment – Basic
Searching
Indexing
Parsing
From Input
Forwarders
Splunk Deployment - Distributed
Search Head
Indexer
Forwarder
Deployment
Server
Index DBs in splunk
• Hot bucket
• Warm bucket
• Cold bucket
• Frozen bucket thawed bucket
Licensing
Splunk license meters works based on the amount of data indexed per
day.
For more details on splunk license, refer :
https://docs.splunk.com/Documentation/Splunk/6.4.2/Admin/Manage
yourlicenses
Splunk Directory structure
• $ SPLUNK_HOME - C:\Program Files\Splunk (for windows)
SPLUNK_HOME
indexes