Splunk Architecture has the following three components:
- Splunk Forwarder: This is used to gather and forward the real-time data with less processing power
- Splunk Indexer: This is used for parsing and indexing data so that it is easy to perform search operations.
- Search Head: This is the user interface where the user can retrieve the data based on the keywords
In case you want to learn Splunk, I strongly recommend this Splunk Training program by Intellipaat.
You can watch this video on Splunk in 30 minutes to know the architecture of Splunk: