For a number of years now I have been successfully architecturing, deploying, maintaining, updating/upgrading and extensively using various versions, flavors (Cloud, On-Premise; "classic" vs. containerized) etc. of Splunk (Enterprise Security), probably my favorite SIEM platform.

 

These are some of the combinations:

  • Splunk on Windows Server + UFs (Windows, Linux) - all On-Prem, built and maintained myself
  • Splunk Cloud ES + On-Prem UFs (Windows, Linux) (a SaaS solution; standardly offered by Splunk, hosted on AWS), built and maintained myself
  • Splunk / ES on AWS + On-Prem UFs (Windows), built and maintained myself
  • Splunk on Linux Server (Cent OS), Multisite Indexer Cluster Configuration with HFs, UFs; Search Head Cluster - done by me: maintenance (incl. repairs and tweaks), DB Connect and other respective updates, creation of TAs and Apps, searches (SPL), alerts, adjusting Dashboards; preparation for Automation via Ansible; extensive troubleshooting of the whole platform etc.
  • Splunk mit Splunkenizer from Marco Stadler, OpenShift, 4 Environments (Test, Dev, Pre-Prod, Prod) - distributed (SHCs, Multisite + a separate ES Search Head etc.)