#Random
This is a place to discuss all things outside of Splunk, its products, and its use cases.

Service level agreement on data loss

sowjanyap2602
New Member

Splunk as product what is the percentage that splunk assures on no data loss.
Is there anything like 99 % or 99.99%
Any document for reference would be helpful

0 Karma

nickhills
Ultra Champion

Your question is not something Splunk can calculate for you.

Failure of hardware is (eventually) inevitable.
If you store one copy of data on a disk it will at some point in the future be lost.
How long this is likely to take depends on many (many) factors, but lets assume you only consider HDD failure.
What is the SLA on your hard disk? - You don't have one. Manufacturers may warrantee or provide a MTBF value, but not an SLA.

SLAs are offered by estimating likely failures over time and cost, the basic HDD failure example can be improved by adding additional HDDs and/or using RAID. You can start to wrap SLAs around raid sets be ensuring you have sufficient spindles in your array and sufficient human resources (technicians, ops staff, stock management, replacement parts logistics etc) to maintain the solution.

Splunk is exactly the same. The Splunk architecture allows you to design for High Availability and Fault tolerance, how far you take it becomes a business decision based on cost.

Commonly, Splunk Architects will deploy a solution based on:
- your desired "search range" (how long do you need to keep data searchable),
- your overall retention period (how long must you keep data for, even if not immediately searchable)
- your desired search and replication factor (how long does a failure take to remedy, and how many Splunk server failures should the deployment tolerate)

Its a very complicated question, and not something Splunk, PS, your Ops Team or your Hardware vendor can answer on their own.
(Even then, SLA accuracies are frequently contested and argued in my experience)

If data durability is of significant concern to your business, you could do a lot worse than use Splunk SmartStore. This writes your data to an Amazon s3 bucket (or compatible storage platform)
If you use AWS, you will get a data DURABILITY (not availability) of 99.99999999% (11 9's)

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

If my answer helped, please consider accepting and/or upvoting so that other memebers of the community can see it was useful.

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

Are you asking about Splunk Enterprise (which you install and run) or Splunk Cloud?

If my comment helps, please give it a thumbs up!
0 Karma

sowjanyap2602
New Member

Splunk Enterpirise which we set up for an organisation

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...