November 2018
Beginner
298 pages
7h 51m
English
It may also be helpful to define the difference between distributed and clustered Splunk deployments before we go further.
In a non-distributed, non-clustered environment, you will have Splunk Enterprise installed on a single server instance—this single machine handles all of the indexing of data and searches of that data (as well as all the other Splunk functions).
A distributed environment describes the separation of indexing and searching logic in Splunk. In the simplest example of a distributed environment, the indexing and search functions are divided across at least two machines—an indexer on one server that receives and indexes data, and a search head on a separate server that communicates ...
Read now
Unlock full access