It is essential to create and maintain documentation for your Splunk deployment so that administration personnel can understand and effectively troubleshoot the environment, and assist in further architectural planning. This documentation should include, as a minimum, an accurate diagram depicting all the Splunk components and how they are connected, and a record of the significant configuration files (server.conf, web.conf, and so on) that governs the specific functionality of each component.
The diagram of the Splunk deployment should include each environment (dev/test and production, and so on) and depict the different sites if applicable. Within each environment, you can use an icon and/or text box representing each of the Splunk components with the following information associated with each component (as a minimum):
- Function(s) (search...