Monitoring Splunk

Any concern to use Splunk directly on the servers where the critical applications are running?

xiaotao
New Member

Hiya

Thinking of using Splunk but worry Splunk takes too much PC resources if use it directly on the servers where the critical applications are running. Any concern at all? Or we should copy the files out to another server/or NAS etc and use Splunk there ??

Many thanks.

Tags (1)
0 Karma

Branden
Builder

Personally, I would recommend keeping your indexer on its own server. Our Splunk indexer is very memory and CPU intensive, so much so that it could interfere with other running applications.

We put SplunkLightForwarders on our application servers and simply have the logs forwarded to the indexer.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...