Deployment Architecture

Horizontal or Vertical scaling for best search head performance

richnavis
Contributor

Hello, I've already read the Splunk planning for a large scale deployment documents. However, I didn't get a sense about what would be better for scaling searchheads... adding more servers or adding processors to existing servers. We have a lot of utility hardware and are debating whether we'd get better performance by adding 4 searchheads with 2socket/4core procs, or adding adding 2 searchheads with 4 socket 4 procs, given equal memory/processor speed and ignoring the differences in OS and Hardware Management, does anyone see a PERFORMANCE BASED reason to choose one or the other?

0 Karma

Damien_Dallimor
Ultra Champion

As dwaddle states, there are also HA considerations.
But from a performance point of view , what are the expectations with respect to :

1) max concurrent users

2) max concurrent searches(inline and scheduled)

0 Karma

richnavis
Contributor

Sometimes we have 20+ users doing needle in haystack type searches. From a concurrent searches perspective, we make extensive use of Views and scheduled searches.. so sometimes close to 40/50 concurrent searches..

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Well, this isn't strictly a performance concern, but with more horizontal search heads you either need search head pooling (which you may wind up with using 2 search heads anyway, depending on how highly available you wish do configure) -- and this brings with it the need for highly-available, high-performance NFS. All things being otherwise equal, I think my preference would be for two larger search heads.

0 Karma

richnavis
Contributor

Thanks for the reply... Yes, I am aware of the HA considerations, and the complications of Search head pooling. In order to simplify the answer, I tried to have the focus be on "Performance based reasons" only..

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...