Which components make up a distributed Splunk Enterprise deployment, and what does each do?
Forwarders collect and send data, indexers parse and store it and answer searches over it, and search heads distribute searches to the indexers (search peers) and merge the results for the user.
* Scale out: more data, more indexers; more users, more search heads. *
| Component | Role |
|---|---|
| Forwarder | Runs on or near the data source and sends data to an indexer (or another forwarder). The lightweight Universal Forwarder is what gets installed on servers and workstations. |
| Receiver | Any Splunk instance configured to accept data from forwarders. |
| Indexer | Turns raw data into events, stores them in indexes, and searches its own data when asked. |
| Search head | Accepts user searches, sends them to the indexers, merges the partial results. |
| Search peer | An indexer answering a search head's request. |
The split lets Splunk scale horizontally: more data → more indexers, more users → more search heads, and each indexer searches only its own share in parallel. In a lab everything runs in one instance, which plays all roles at once.
For the Sysmon lab this means: a Universal Forwarder on the Windows host reads the Microsoft-Windows-Sysmon/Operational channel and ships it to the indexer.
Go deeper:
Splunk — Components and the data pipeline — forwarders, indexers and search heads and which stage each handles.