Match each Splunk component to its function.
Drag a concept onto its matching description — or click a concept then click the description.
Indexes and stores incoming data
Distributes search requests and merges results
Sends data to indexers or other forwarders
Manages configuration of forwarders
Manages license usage across the deployment
Why these pairings
In a Splunk distributed environment, the Search Head handles search distribution and result merging, the Indexer indexes and stores data, the Universal Forwarder collects and forwards data, and the Deployment Server manages configuration deployment. Common mistakes include swapping the roles of Search Head and Indexer, or confusing the Deployment Server with a forwarder.