Splunk Stream on-premise deployment architecture (2024)

To deploy Splunk Stream you install three Stream components on your Splunk software.

Product nameInstallation package nameInstalled file name
Splunk App for Streamsplunk_app_streamsplunk_app_stream/
Splunk Add-on for Stream ForwardersSplunk_TA_streamSplunk_TA_stream/
Splunk Add-on for Stream Wire DataSplunk_TA_stream_wire_dataSplunk_TA_stream_wire_data/

Splunk Stream also provides Independent Stream Forwarders (ISF). ISF installation is packaged as a binary file <streamfwd> in the Splunk App for Stream package.

For more about Splunk Stream components, see Splunk Stream installation package overview in this manual.

Splunk Stream supports most deployment architectures:

  • Managed Splunk Cloud deployments
  • Distributed deployment configurations, including deployment servers and indexer clusters
  • Single instance deployments, where a single instance of Splunk Enterprise is both the indexer and the search head
  • Independent Stream Forwarders (ISF) on compatible Linux machines

Single instance deployment

When you install Splunk Stream on a single Splunk Enterprise instance, that instance serves as both search head and indexer and provides both search and storage capability. A single instance deployment can support one or two users running concurrent searches, which is ideal for a small test environment. For single instance installation instructions, see Install Splunk Stream on a single instance in this manual.

Distributed Splunk Stream deployment

A Splunk Stream distributed deployment can capture network event data from multiple network devices, including NICs, switches, and routers. A distributed deployment can be used in medium and large enterprise network infrastructures. For distributed installation instructions, see Install Splunk Stream in a distributed environment in this manual.

A distributed deployment for Splunk Stream includes the following deployment locations and Splunk Stream components:

Splunk deployment locationSplunk Stream component
search headsThe Splunk App for Stream (splunk_app_stream) and Splunk Add-on for Stream Wire data (Splunk_TA_stream_wire_data) must be installed on search heads.

You can optionally install Splunk Add-on for Stream Forwarders (splunk_TA_stream) if you want to collect data from the search head or want to use the PCAP upload.

indexersSplunk Add-on for Stream Wire Data (Splunk_TA_stream_wire_data) must be installed on all indexers for searching and parsing. Splunk Add-on for Stream Wire Data contains both search and index time knowledge objects.
universal forwardersThe Splunk Add-on for Stream Forwarders (Splunk_TA_stream) must be installed on universal forwarders where you want to capture network data. For dedicated wire capture in Linux environments without a universal forwarder, use the Independent Stream Forwarder (ISF). For more information, see Network collection architectures in this manual
heavy forwarderIf you use a heavy forwarder in your Splunk Stream configuration, the Splunk Add-on for Stream Forwarders (Splunk_TA_stream) must be installed on universal or heavy forwarders where you want to capture network data. You must also install the Add-on for Stream Wire Data (Splunk_TA_stream_wire_data) on your heavy forwarder wherever that index performs pipeline processing.
deployment serverUse the Splunk deployment server to distribute The Splunk Add-on for Stream Forwarders package (Splunk_TA_stream) to universal forwarders across a distributed deployment. When you upgrade to a new version of Splunk Stream, the deployment server detects whether a new version of The Splunk Add-on for Stream Forwarders exists. If a new version is found, all universal forwarders subscribed as deployment clients pull and install the new version of the add-on. For more information, see
  • Deployment server provisioning in Upgrading Splunk Enterprise Instances.
  • Components of a Splunk Enterprise deployment in the Splunk Enterprise Capacity Planning Manual.
Independent Stream Forwarder (ISF)The ISF is a standalone Stream forwarder. The ISF sends captured network data to Splunk using the HTTP event collector, and does not require a Splunk universal forwarder to collect wire data. It is helpful in networks and deployments where a universal forwarder cannot be installed. See Install an Independent Stream Forwarder

How a distributed Splunk Stream deployment works

In a typical distributed deployment, the Splunk Add-on for Stream Forwarders is installed on universal forwarders as Splunk_TA_Stream. Once installed, the forwarder captures network event data on local NICs, such as each node of a subnet environment, or from a network SPAN or TAP. For more information about data collection, see Network collection architectures in this manual.

The network data that a Stream forwarder captures depends on the specific protocols and fields that you select when you configure a stream using the Configure Streams UI that the Splunk App for Stream provides when you install it. The Stream forwarder sends that captured event data to indexers using the Splunk Add-on for Stream Wire Data (Splunk_TA_stream_wire_data).

Splunk_TA_stream/local/inputs.conf stores the location of the Splunk App for Stream (splunk_app_stream) installation, . The Stream forwarder uses this location to ping the Splunk App For Stream over HTTP port 8000. If the Stream forwarder detects a change in the Splunk Stream configuration, the Stream forwarder sends an API request to the endpoint to get the latest configuration data.

For more information about configuring the Splunk Add-on for Stream Forwarders, see Configure Stream Forwarders in this manual.

Splunk Stream on-premise deployment architecture (2024)

FAQs

Can Splunk be deployed on premise? ›

You can deploy Splunk Enterprise Security on-premises and on Splunk Cloud Platform.

Which architectural component of a Splunk deployment initiates a search in Splunk? ›

The search head provides the UI users can use to interact with Splunk. It allows users to search and query Splunk data, and interfaces with indexers to gain access to the specific data they request.

What are the minimum requirements for Splunk deployment server? ›

there isn't a reference hardware for the Deployment Server. The only indication is that is a standard Splunk server, so at least 12 CPUs and 12 GB RAM. In general, you can use also less resources (8+8).

What are the three main components of Splunk? ›

In general, they are three components in Splunk.
  • Splunk Forwarder: which is used to forward the data.
  • Splunk Indexer: which is used for Parsing data and Indexing the data.
  • Search Head: It is User interface where the user will have an option to search, analyze and report data.

How to do on premise deployment? ›

Finance + Operations (on-premises) bits are distributed through Microsoft Dynamics Lifecycle Services. Before you can deploy, you must purchase license keys through the Enterprise Agreements channel and set up an on-premises project in Lifecycle Services. Deployments can be initiated only through Lifecycle Services.

Is Splunk on Prem or cloud? ›

Splunk Enterprise is typically deployed on-premises or in a private cloud, while Splunk Cloud is a fully managed cloud-based offering provided by Splunk.

What are the 4 types of searches in Splunk by performance? ›

How search types affect Splunk Enterprise performance
Search typeRef. indexer throughputPerformance impact
DenseUp to 50,000 matching events per second.CPU-bound
SparseUp to 5,000 matching events per second.CPU-bound
Super-sparseUp to 2 seconds per index bucket.I/O bound
RareFrom 10 to 50 index buckets per second.I/O bound

Which are types of Splunk platform deployments? ›

These are some of the main types of deployments, based on size:
  • Departmental. A single instance that combines indexing and search management functions.
  • Small enterprise. One search head with two or three indexers.
  • Medium enterprise. A small search head cluster, with several indexers.
  • Large enterprise.
Sep 4, 2015

What are the 3 modes in Splunk search? ›

Search mode has three settings: Fast, Verbose, and Smart.

How does deployment server work in Splunk? ›

In this example, each deployment client is a Splunk Enterprise forwarder that belongs to two server classes, one for its OS and the other for its geographical location. The deployment server maintains the list of server classes and uses those server classes to determine what content to distribute to each client.

Does a Splunk deployment server need a license? ›

All Splunk Enterprise instances functioning as management components need access to an Enterprise license. Management components include the deployment server, the indexer cluster manager node, the search head cluster deployer, and the monitoring console.

Which of the Splunk components is connected with deployment server? ›

The deployment server is the tool for distributing configurations, apps, and content updates to groups of Splunk Enterprise instances. You can use it to distribute updates to most types of Splunk Enterprise components: forwarders, non-clustered indexers, and search heads.

What are some of the most important configuration files in Splunk? ›

List of Splunk Configuration Files
Configuration filePurpose
app.confConfigure app properties
authentication.confToggle between Splunk's built-in authentication or LDAP, and configures LDAP
authorize.confConfigure roles, including granular access controls.
collections.confConfigure KV Store collections for apps.
15 more rows
Mar 21, 2023

What are 2 features of Splunk? ›

Features of Splunk
  • Accelerate development and testing. ...
  • Build real-time data applications. ...
  • ROI generation. ...
  • Agile statistics and reporting with real-time architecture. ...
  • Offers search, analysis, and visualization capabilities to empower users of all types.

Can Threat Grid be deployed on premise? ›

On premises

The appliances provide highly secure malware analysis and advanced sandboxing. Information is kept on site. The appliance may be configured to share sample data with integrating devices.

Can SaaS be deployed on premise? ›

SaaS flexibility

For instance, you can choose SaaS products that connect to data sources you control—either in your cloud account or on premises. You can also choose SaaS offerings that augment your existing on-premises or cloud applications.

Can Splunk run in a container? ›

You can deploy Splunk Enterprise inside a Docker container by downloading and launching the required Splunk Enterprise image in Docker. The image is an executable package that includes everything you need to run Splunk Enterprise. For universal forwarder instructions, see the Universal Forwarder manual.

Top Articles
Actually, There Are Perfectly Rational Reasons for Republicans to Be Mad About That Supreme Court Leak
WATCH : Aria Electra Baby Alien Fanbus Video Viral Baby Alien Fan Van Video dwu | vefkos
PBC: News & Top Stories
Sarah Burton Is Givenchy's New Creative Director
Smsgt Promotion List
Retail Space For Rent Craigslist
Can Banks Take Your Money To Pay Off Debts? StepChange
Four Brothers 123Movies
Climate change, eroding shorelines and the race to save Indigenous history - The Weather Network
Ascension St. Vincent's Lung Institute - Riverside
Cbs Week 10 Trade Value Chart
Busted Newspaper Randolph County Missouri
5 Best Brokerage Accounts for High Interest Rates on Cash Sweep - NerdWallet
Busted Newspaper Hart County Ky
The Nun 2 Showtimes Tinseltown
Northwell.myexperience
PNC Bank Review 2024
Cbs Local News Sacramento
Bones And All Showtimes Near Tucson Spectrum 18
Ar Kendrithyst
Mcallen Craiglist
Gina's Pizza Port Charlotte Fl
Craigslist Parsippany Nj Rooms For Rent
More Apt To Complain Crossword
Watch Psychological Movies Online for FREE | 123Movies
Journal articles: 'Mark P. Herschede Trust' – Grafiati
Walmart Phone Number Auto Center
Nicolas Alexander Portobanco
Pair sentenced for May 2023 murder of Roger Driesel
R Toronto Blue Jays
Sdn Upstate 2023
Couches To Curios Photos
Baldurs Gate 3 Igg
Https Eresponse Tarrantcounty Com
A Closer Look at Ot Megan Age: From TikTok Star to Media Sensation
Dr Yakubu Riverview
Valentino Garavani Flip Flops
Ignition Date Format
454 Cubic Inches To Litres
Best Hair Salon Dublin | Hairdressers Dublin | Boombae
Lvpg Orthopedics And Sports Medicine Muhlenberg
Babbychula
Walmart Careers Application Part Time
Walgreens Pharmacy On Jennings Station Road
Lagniappemobile
Huskersillustrated Husker Board
Burkes Outlet Credit Card Sign In
Now 81, Wayne Newton Will Soon Mark 65 Years as Mr. Las Vegas
GW2 Fractured update patch notes 26th Nov 2013
Meggen Nut
Jersey Mike's Subs: 16 Facts About The Sandwich Chain - The Daily Meal
Online-Shopping bei Temu: Solltest du lieber die Finger davon lassen?
Latest Posts
Article information

Author: Foster Heidenreich CPA

Last Updated:

Views: 5591

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Foster Heidenreich CPA

Birthday: 1995-01-14

Address: 55021 Usha Garden, North Larisa, DE 19209

Phone: +6812240846623

Job: Corporate Healthcare Strategist

Hobby: Singing, Listening to music, Rafting, LARPing, Gardening, Quilting, Rappelling

Introduction: My name is Foster Heidenreich CPA, I am a delightful, quaint, glorious, quaint, faithful, enchanting, fine person who loves writing and wants to share my knowledge and understanding with you.