Splunk Enterprise Administration: Configuring Distributed Search

You will gain an understanding of how Splunk executes a search and how Splunk distributes a search across a set of indexers.
Course info
Level
Intermediate
Updated
Sep 1, 2020
Duration
1h 31m
Table of contents
Description
Course info
Level
Intermediate
Updated
Sep 1, 2020
Duration
1h 31m
Description

Learning to configure a distributed search doesn't need to be difficult. In this course, Splunk Enterprise Administration: Configuring Distributed Search, you'll gain the ability to configure Splunk platform correctly for efficient searching. First, you'll explore the anatomy of a search. Next, you'll discover how Splunk separates search management and presentation layers from indexing and search retrieval layers. Finally, you'll learn what knowledge bundles are and how Splunk manages knowledge bundles. When you are finished with this course, you'll have the skills and knowledge of how to configure distributed search groups needed to scale options available for distributed search.

About the author
About the author

Passionate about IT Ops, Karun has 20+ years of hands on experience with Linux, Cloud tech, Monitoring and Log aggregation. He enjoys creating learning materials that are engaging and provide immediate practical value.

More from the author
More courses by Karun Subramanian
Section Introduction Transcripts
Section Introduction Transcripts

Course Overview
Hi everyone, my name is Karun Subramanian, and welcome to my course, Splunk Enterprise Administration: Configuring Distributed Search. I am an IT operations expert and Splunk Certified Architect. I have architected and implemented many large‑scale Splunk installations. Splunk is the Google for operational big data, and as a Splunk administrator, it is your job to configure the platform so that it produces accurate results fast. In this course, you are going to learn about distributed search, how Splunk separates search management and presentation layer from indexing and data retrieval layer. You'll gain the knowledge of search peers, search knowledge bundles, and scaling options available for distributed search. Some of the major topics we will cover include data flow in a distributed search, configuring indexers as search peers, tuning knowledge bundle replication, and search head cluster architecture. By the end of this course, you'll know how to configure distributed search end to end whether you have three search peers or 300 search peers. Before beginning this course, you should be familiar with Splunk Web interface, basic Splunk product architecture. I hope you'll join me on this journey to learn how to set up your Splunk enterprise for maximum search efficiency with the Splunk Enterprise Administration: Configuring Distributed Search course, at Pluralsight.