Hi All,
Can anyone please advise me regarding the Splunk Engineering limits documents. What i am looking for is :-
etc etc
Thanks in advance.
I agree, your questions really pertain to hardware rather than the core software. I suggest you read Hardware capacity planning for your Splunk deployment in the Installation Manual for some guidance.
Going by the Splunk guidelines doc is good for a start. We've found that the ability to laterally upgrade by just adding more indexers has been a very viable solution (even if the hardware is not that great). At the moment we're using 4 Indexers that are now over 3 year old hardware, easily handling ~80GB a day. One thing to NOT skimp on is your I/O back-end. Get the fastest disks you possibly can, preferably RAID10.
Thanks for your Response. Appreciate that.
I agree, your questions really pertain to hardware rather than the core software. I suggest you read Hardware capacity planning for your Splunk deployment in the Installation Manual for some guidance.
Thanks for your Response. Appreciate that.
I believe this is more a limitation of your hardware than the Splunk software. I personally have easily done 150GB in a day of data. I there are customers out there that are doing around 1TB or more of data a day.
Thanks for your Response. Appreciate that.