Indiana University implemented a centralized Splunk deployment to provide log management services across the university's decentralized IT environment. They developed a scalable multi-tenant architecture using deployment servers, forwarders, and a search head cluster. To onboard new customers, they created a script that automatically configures forwarders, indexes data by department, and applies the necessary configurations. Over time, they expanded their services by refining their apps, training customers, and increasing the number of departments and servers supported. Their goal is to further develop apps to help audit compliance and expand Splunk's use for additional IT systems across the university.