How to determine if Splunk needs to be scaled horizontally or vertically? For logs up to 5GB from different inputs, what should be the ideal setup?
You need to add indexers once you hit about 250GB/day of input.
https://www.splunk.com/blog/2014/05/07/splunk-sizing-and-performance-doing-more-with-more.html
up to 5GB dont scale,
stay at a single instance and you will do great