Monitoring Splunk

Any concern to use Splunk directly on the servers where the critical applications are running?

xiaotao
New Member

Hiya

Thinking of using Splunk but worry Splunk takes too much PC resources if use it directly on the servers where the critical applications are running. Any concern at all? Or we should copy the files out to another server/or NAS etc and use Splunk there ??

Many thanks.

Tags (1)
0 Karma

Branden
Builder

Personally, I would recommend keeping your indexer on its own server. Our Splunk indexer is very memory and CPU intensive, so much so that it could interfere with other running applications.

We put SplunkLightForwarders on our application servers and simply have the logs forwarded to the indexer.

Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...