Enterprise Splunk deployments use a distributed architecture: Search Head Cluster (SHC) for search resilience and load balancing, Indexer Cluster for data replication and availability, and a Cluster Manager (formerly Master Node) for indexer coordination. The architect sizes each component based on search concurrency, ingest volume, and availability requirements.
The Search Head Cluster requires a minimum of 3 members with a Deployer for app distribution. Replication factor (RF) and search factor (SF) govern indexer cluster data protection. A common production configuration is RF=3, SF=2, meaning 3 copies of data exist and 2 must be searchable at all times.