LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

Which components make up a distributed Splunk Enterprise deployment, and what does each do?

Forwarders collect and send data, indexers parse and store it and answer searches over it, and search heads distribute searches to the indexers (search peers) and merge the results for the user.

Forwarders send data to two indexers; the search head sends searches to both indexers and merges the results for the analyst

* Scale out: more data, more indexers; more users, more search heads. *

Component Role
Forwarder Runs on or near the data source and sends data to an indexer (or another forwarder). The lightweight Universal Forwarder is what gets installed on servers and workstations.
Receiver Any Splunk instance configured to accept data from forwarders.
Indexer Turns raw data into events, stores them in indexes, and searches its own data when asked.
Search head Accepts user searches, sends them to the indexers, merges the partial results.
Search peer An indexer answering a search head's request.

The split lets Splunk scale horizontally: more data → more indexers, more users → more search heads, and each indexer searches only its own share in parallel. In a lab everything runs in one instance, which plays all roles at once.

For the Sysmon lab this means: a Universal Forwarder on the Windows host reads the Microsoft-Windows-Sysmon/Operational channel and ships it to the indexer.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026