⛏️ Get Splunky!
Lv.1Intern
0 XP
0
Home Map Stats Drill Board Log In
Back to Floor
Scale Lab • Room 1

Splunk Deployment Architecture at Scale

Enterprise Splunk deployments use a distributed architecture: Search Head Cluster (SHC) for search resilience and load balancing, Indexer Cluster for data replication and availability, and a Cluster Manager (formerly Master Node) for indexer coordination. The architect sizes each component based on search concurrency, ingest volume, and availability requirements.

The Search Head Cluster requires a minimum of 3 members with a Deployer for app distribution. Replication factor (RF) and search factor (SF) govern indexer cluster data protection. A common production configuration is RF=3, SF=2, meaning 3 copies of data exist and 2 must be searchable at all times.

Knowledge Check

Prove your understanding to clear the room (Rewards XP)
In an Indexer Cluster, what do RF and SF control?
Replication Factor (RF) controls how many of data exist. Search Factor (SF) controls how many copies must be at all times.