When you first started Splunk, you probably installed it on one machine, imported some logs, and got to work searching. It is wonderful that you can try out the product so easily, but once you move into testing and production, things can get much more complicated, and a bit of planning will save you from trouble later.
In this chapter, we will discuss the following topics:
- Getting data
- The different parts of a distributed deployment
- Distributed configuration management
- Sizing your installation
- Security concerns
- Backup strategies