Deployment Architecture

Local log storage

ebdavison
New Member

My only previous experience with Splunk was in the every beginning and I have been asked to look at this again. In the beginning all logs were sent up to splunk servers for storage and analysis. I cannot tell definitively whether this is still the case.

If I download either the free or the enterprise version, are the logs stored locally ONLY? This is very important due to the nature of our logs.

Is there any information that is forwarded to splunk servers?

Tags (1)
0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

When you run Splunk (either free or enterprise), nodes are divided up into two classes - indexers and forwarders. Forwarders forward log data to indexers who store it on their locally attached disks. (A bit of an oversimplification here, because forwarders can index locally before forwarding and so on, but for purpose of answering your question it's close enough)

At least with current versions of Splunk (4.0 and above - I have no personal experience with prior versions), neither forwarders nor indexers send your log data to servers outside of your control. (That is, unless you configure them explicitly to do so). Your data is NEVER sent to a Splunk.com repository in the sky.

View solution in original post

LCM
Contributor

Not sure what exactly you mean - maybe you re-describe it more clearly! (like, what is your environment look like at the moment, where are your logs right now, and what do you want to do with it -> with splunk)

Just as much: You either can store your data "locally" or send it further to another "device" or both!

You also may check out: http://www.splunk.com/base/Documentation/latest/Admin/Whatsinthismanual

dwaddle
SplunkTrust
SplunkTrust

When you run Splunk (either free or enterprise), nodes are divided up into two classes - indexers and forwarders. Forwarders forward log data to indexers who store it on their locally attached disks. (A bit of an oversimplification here, because forwarders can index locally before forwarding and so on, but for purpose of answering your question it's close enough)

At least with current versions of Splunk (4.0 and above - I have no personal experience with prior versions), neither forwarders nor indexers send your log data to servers outside of your control. (That is, unless you configure them explicitly to do so). Your data is NEVER sent to a Splunk.com repository in the sky.

ebdavison
New Member

Thanks, that helps to clarify the storage for me. When Splunk was first released all that was available was a forwarder for download. Splunk had the only indexers. Now I can see this is now offered locally for both services.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...