January 2013
Beginner to intermediate
448 pages
9h 16m
English
When you first started Splunk, you probably installed it on one machine, imported some logs, and got to work searching. It is wonderful that you can try the product out so easily, but once you move into testing and production, things can get much more complicated, and a bit of planning will save you from trouble later.
In this chapter, we will discuss getting data in, the different parts of a distributed deployment, distributed configuration management, sizing your installation, security concerns, and backup strategies.
There are a few questions that you need to answer to determine how many Splunk instances will be involved in your deployment:
Read now
Unlock full access