Monitoring logs on servers

In this scenario, servers write their logs to a local drive, and a forwarder process monitors these logs. This is the typical Splunk installation.

The advantages of this approach include the following:

The disadvantages of this approach include the following:

This is usually not a problem but does require some planning. This typical deployment looks like the following diagram:

If your log volume exceeds 100 gigabytes of logs produced each day, you need to think about multiple indexers. We will talk about this further in the Sizing indexers section.