<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Distributed search sizing in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-sizing/m-p/55115#M1796</link>
    <description>&lt;P&gt;I agree your suggestion. This is appropriate sizing with considering to future plan. My answer was rough idea.&lt;/P&gt;</description>
    <pubDate>Fri, 18 May 2012 00:47:49 GMT</pubDate>
    <dc:creator>Takajian</dc:creator>
    <dc:date>2012-05-18T00:47:49Z</dc:date>
    <item>
      <title>Distributed search sizing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-sizing/m-p/55112#M1793</link>
      <description>&lt;P&gt;I've looked through some of the documentation for separating search heads from indexers depending on the number of concurrent searches and users.  I'm wondering what a rough idea of the architecture and hardware requirements would look like to support:&lt;/P&gt;

&lt;P&gt;10-20 GB per day&lt;BR /&gt;
20 concurrent users&lt;BR /&gt;
10 concurrent saved searches&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2012 21:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-sizing/m-p/55112#M1793</guid>
      <dc:creator>ontai</dc:creator>
      <dc:date>2012-05-17T21:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search sizing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-sizing/m-p/55113#M1794</link>
      <description>&lt;P&gt;I do not think you do not need dedicated search head when  you index data less than 100GB per day on one box server. You can also refer to following site. Hope this help.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/installation/capacityplanningforalargersplunkdeployment"&gt;http://docs.splunk.com/Documentation/Splunk/latest/installation/capacityplanningforalargersplunkdeployment&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2012 23:16:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-sizing/m-p/55113#M1794</guid>
      <dc:creator>Takajian</dc:creator>
      <dc:date>2012-05-17T23:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search sizing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-sizing/m-p/55114#M1795</link>
      <description>&lt;P&gt;Given your user and scheduler concurrency, you would probably be best off implementing an indexer and a search head.  Although you can easily index 80-100 GB/day on a single commodity server, having 20 concurrent users and 10+ concurrent scheduled searches on the same machine wouldn't allow for the best user experience or much room for growth.&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2012 00:43:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-sizing/m-p/55114#M1795</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-05-18T00:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed search sizing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-sizing/m-p/55115#M1796</link>
      <description>&lt;P&gt;I agree your suggestion. This is appropriate sizing with considering to future plan. My answer was rough idea.&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2012 00:47:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-search-sizing/m-p/55115#M1796</guid>
      <dc:creator>Takajian</dc:creator>
      <dc:date>2012-05-18T00:47:49Z</dc:date>
    </item>
  </channel>
</rss>

