Professional Documents
Culture Documents
⇢ Deployment models
⇢ Storing data on disk
⇢ Licensing
⇢ Apps and add-ons
Deployment Models
Splunk Deployment Models
Cloud On Premises
The Splunk Data Pipeline
Input
Parsing
Indexing
• Data divided into events. Writes the data to the disk in "buckets"
Searching
$SPLUNK_HOME/var/lib/splunk/defaultdb/db/*
$SPLUNK_HOME/var/lib/splunk/defaultdb/colddb/*
$SPLUNK_HOME/var/lib/splunk/defaultdb/thaweddb/*
Enterprise
Standard Sales Trial Dev/Test
Trial
Industrial
Free Forwarder
IoT
No
Warning Violation enforcement
Apps Add-ons
Visualization Data enrichment
Analysis Tags
foo.conf
bar.conf
baz.conf
Premium Free
Splunk Built
AppInspect Passed