In a single-instance deployment, one Splunk server handles all functions: data collection, indexing, and searching. This is fine for small environments or testing.
In a distributed deployment, these roles are split across multiple servers for scalability and performance. Search Heads, Indexers, and Forwarders each run on dedicated machines.
Most production environments use distributed deployments. As data volume grows, you scale by adding more Indexers and Forwarders.