Splunk

Overview

Indexer

Splunk indexer processes data it receives from the forwarder and organizes it, then stores them as events

Search Head

Search head is used to search through the indexed logs, you can also use it to create visualizations of the data

Forwarder

Splunk forwarder is used to collect data and send it to Splunk.

Splunk Navigation

Splunk Bar

Apps Panel

Installed applications can be listed and accessed here (Default app is "Search & Reporting")

Explore Splunk

Quick access links to add data to splunk (Apps, data, documentation, etc.)

Splunk Dashboard

Visualizations of data in Splunk