> For the complete documentation index, see [llms.txt](https://topgeartraining.gitbook.io/focus2learn/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://topgeartraining.gitbook.io/focus2learn/architectures/splunk-es.md).

# Splunk ES

## :heavy\_check\_mark:Splunk Architecture

![](https://1771079106-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MQbAc68qKpvpcr7cwG8%2F-MRiYpjmOmZ7AX8mZkFV%2F-MRiZxZE8goIM1cWlUoc%2Fimage.png?alt=media\&token=9957b233-9127-4434-803d-a8e81ae518ab)

### &#x20;:heavy\_check\_mark:Splunk Components

![](https://1771079106-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MQbAc68qKpvpcr7cwG8%2F-MRiT4U44Qj5fARfdze2%2F-MRiWy_R5akSwY7GzlJo%2Fimage.png?alt=media\&token=3943a56b-e3b1-4f4c-b553-93b79ce9420a)

{% tabs %}
{% tab title="Forwarder" %}

* Useful for collecting the logs from a remote machine, which will forward the log data to a Splunk Indexer for processing and storage.&#x20;

**Types:**

* &#x20;**Universal Forwarder** – You can opt for an universal forwarder if you want to forward the raw data collected at the source. It is a simple component which performs minimal processing on the incoming data streams before forwarding them to an indexer.
* **Heavyweight Forwarder (HWF)** –  **Heavy Forwarder** – You can use a Heavy forwarder and eliminate half your problems, because one level of data processing happens at the source itself before forwarding data to the indexer. Heavy Forwarder typically does parsing and indexing at the source and also intelligently routes the data to the Indexer saving on bandwidth and storage space. So when a heavy forwarder parses the data, the indexer only needs to handle the indexing segment. [Click Here](https://www.edureka.co/blog/splunk-architecture/)

![](https://1771079106-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MQbAc68qKpvpcr7cwG8%2F-MRieV21fT_5l71AoCoI%2F-MRieh_YNw4GQV1grKTD%2Fimage.png?alt=media\&token=dfe5973a-9d48-48d0-b80b-330e08a59c2c)
{% endtab %}

{% tab title="Indexer" %}

* Useful for Indexing and Storing the data coming from the forwarder.
* Splunk instance transforms the **incoming data into events** and stores it in indexes for performing search operations efficiently.
* If you are receiving the data from a **Universal forwarder**, then the indexer will **first parse the data** and then **index** it. Parsing of data is done to eliminate the unwanted data. ---> But, if you are receiving the data from a **Heavy forwarder**, the indexer will **only index** the data.
  {% endtab %}

{% tab title="Search Head " %}

* Used for searching, analyzing and reporting.
* We can search and query the data **stored in the Indexer** by entering search words and you will get the expected result.
  {% endtab %}

{% tab title="License Master" %}

* It Make sure that the right amount of data gets indexed.
* Splunk license is based on the **data volume** that comes to the platform within a 24hr window and thus, it is important to make sure that the environment stays within the limits of the purchased volume.
* **If the License Master is unreachable** then it is just **not possible** to **search** the data. However, the data coming in to the Indexer will not be affected.
* So, the indexing does not stop; only searching is halted :exclamation: .
* License Violation [Q-10](https://www.edureka.co/blog/interview-questions/top-splunk-interview-questions-and-answers/)
* [Click Here](https://www.edureka.co/blog/interview-questions/top-splunk-interview-questions-and-answers/)
  {% endtab %}

{% tab title="Parsing vs Normalization" %}
**Parsing = Mapping text into fields**

Given the line:

*Sep 28 16:39:03 app\_server sshd\[8677]: Failed password for invalid user icecast2 from 10.72.109.227 port 57238 ssh2*

It would be parsed into:

&#x20; host = app\_server

&#x20; process = sshd

&#x20; source\_user = icecast2

&#x20; source\_ip = 10.72.109.227

&#x20; source\_port = 57238

and inserted into the database.

**Normalization = Assign category**

For normalization, the event above be assigned a normalization ID of: 409075712 which is Authentication | Login | SSH Login in the normalization taxonomy.

![](https://1771079106-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MQbAc68qKpvpcr7cwG8%2F-MSa_Kw2SRkd52Sq0mjs%2F-MSa_RJpBBaTR1lJO_la%2Fimage.png?alt=media\&token=cef2fa37-050a-40ac-b04e-8e33d8c8d4b0)

If I use the Normalized group, SSH Login, as a filter, it will show me all events categorized as SSH logins regardless of the originating device, OS or signature ID.

![](https://1771079106-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MQbAc68qKpvpcr7cwG8%2F-MSa_Kw2SRkd52Sq0mjs%2F-MSa__fSU6avV7tGhDVe%2Fimage.png?alt=media\&token=57236e59-f2fd-4167-8897-6dd7afa4a0e1)
{% endtab %}
{% endtabs %}

### :heavy\_check\_mark:Ports used in Splunk

* Splunk Web Port: 8000
* Splunk Management Port: 8089
* Splunk Network port: 514
* Splunk Index Replication Port: 8080
* Splunk Indexing Port: 9997
* KV store: 8191

![](https://1771079106-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MQbAc68qKpvpcr7cwG8%2F-MRiHVqirlHoRkBp4rAM%2F-MRiQsV5Bz8KKyIA-EvL%2Fimage.png?alt=media\&token=eda89e06-c922-4d8c-b247-dd7f6f96e5cb)

## Reference

[Click Here](https://www.edureka.co/blog/splunk-architecture/)
