Deployment Architecture

Splunk on AWS EC2

garfieldconnoll
Explorer

Hi,

We're working with Splunk on Amazon's EC2 service (Ubuntu).

At the moment we're working off a standard instance, at 10cent per hour.

I was going to upgrade to a high CPU medium instance, at 20cent per hour.

With AWS' announcement today regarding micro instances, I was wondering.....

"Am I better with 1 high CPU medium instance, 2 standard instances, or 10 micro instances?"

Okay, so there's a strong "string L=N, derive N" element to the question. But if I had to choose a route, any suggestions?

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

When in AWS, I would recommend scaling using units of the High-CPU XL instances. It seems like you need less capacity than this, but of the choices, I am pretty sure the 10 micro instances will be unsuitable and clumsy for a typical Splunk workload. I think the Standard Small is also too small, even with two of them, as you are limited to just one core per machine. Between the Standard Large and the High-CPU Large, I might go with the High-CPU, unless you plan to store you indexes on the instance rather than on EBS, in which case the additional space on the Standard might count for more.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

When in AWS, I would recommend scaling using units of the High-CPU XL instances. It seems like you need less capacity than this, but of the choices, I am pretty sure the 10 micro instances will be unsuitable and clumsy for a typical Splunk workload. I think the Standard Small is also too small, even with two of them, as you are limited to just one core per machine. Between the Standard Large and the High-CPU Large, I might go with the High-CPU, unless you plan to store you indexes on the instance rather than on EBS, in which case the additional space on the Standard might count for more.

garfieldconnoll
Explorer

Able to thank gkanapathy's response now, so doing so!

0 Karma

garfieldconnoll
Explorer

Thanks for that. I'd +1 the post, but I don't have permission yet. We don't have a lot of data, but may have a disproportionate number of users for the amount of indexed data. Apologies if I have the 'wrong end of the stick' on that.

Regards,

G.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...