Getting Data In

What's the limit of index count per indexer?

Simon
Contributor

Hi everybody

At the moment I've got about 170 indexes on my indexer. I

What's the best practice limit of numbers of indexes per indexer? I've got a 2 x quad core xeon 2.0ghz machine with 16gb memory.

Regards, Simon

Tags (1)
0 Karma
1 Solution

Mick
Splunk Employee
Splunk Employee

Do you mean 170 distinct index directories in $SPLUNK_DB? or 170 buckets across all of your indexes?

There's no hard limit, it's all dependant on the total amount of data you are indexing, your disk and the efficiency of your indexing settings. If you are actively indexing data to every single index, then Splunk may have a hard time keeping up with all of the aggregation, sourcetyping, etc. If you look for messages containing 'blocked!!=true' in the _internal index, that will tell you if you are hitting any resource limitations. CPU time is one possible bottleneck, disk contention is another.

If there are no 'blocked' messages, then that would indicate that your instance is happy and able to cope with the workload. If you're not indexing a high volume of data, I wouldn't expect Splunk to be complaining very much.

View solution in original post

Mick
Splunk Employee
Splunk Employee

Do you mean 170 distinct index directories in $SPLUNK_DB? or 170 buckets across all of your indexes?

There's no hard limit, it's all dependant on the total amount of data you are indexing, your disk and the efficiency of your indexing settings. If you are actively indexing data to every single index, then Splunk may have a hard time keeping up with all of the aggregation, sourcetyping, etc. If you look for messages containing 'blocked!!=true' in the _internal index, that will tell you if you are hitting any resource limitations. CPU time is one possible bottleneck, disk contention is another.

If there are no 'blocked' messages, then that would indicate that your instance is happy and able to cope with the workload. If you're not indexing a high volume of data, I wouldn't expect Splunk to be complaining very much.

Simon
Contributor

Hi Mick

I have 170 seperate indexes, not buckets!
But at the moment I can't find any "blocked" messages.

Well, that helped. Thanks for answering

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...