<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Would Multiple Enterprise Security Splunk Instances Affect Indexing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/569995#M101042</link>
    <description>&lt;P&gt;Currently working on a project where instead of dedicating only a single instance of Splunk only for ES they actually have ES installed on every Search Head. From my experience in tinkering with "&lt;A href="https://splunk-sizing.appspot.com/&amp;quot;" target="_blank"&gt;https://splunk-sizing.appspot.com/"&lt;/A&gt;&amp;nbsp;any time I would pick ES for Search Heads, the automatic amount required for Indexer nodes gets trippled.&lt;/P&gt;&lt;P&gt;I was just wondering maybe if this would help ease the critical pressure that is going on in the indexers at the moment.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Oct 2021 07:36:56 GMT</pubDate>
    <dc:creator>NightShark</dc:creator>
    <dc:date>2021-10-07T07:36:56Z</dc:date>
    <item>
      <title>Would Multiple Enterprise Security Splunk Instances Affect Indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/569995#M101042</link>
      <description>&lt;P&gt;Currently working on a project where instead of dedicating only a single instance of Splunk only for ES they actually have ES installed on every Search Head. From my experience in tinkering with "&lt;A href="https://splunk-sizing.appspot.com/&amp;quot;" target="_blank"&gt;https://splunk-sizing.appspot.com/"&lt;/A&gt;&amp;nbsp;any time I would pick ES for Search Heads, the automatic amount required for Indexer nodes gets trippled.&lt;/P&gt;&lt;P&gt;I was just wondering maybe if this would help ease the critical pressure that is going on in the indexers at the moment.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 07:36:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/569995#M101042</guid>
      <dc:creator>NightShark</dc:creator>
      <dc:date>2021-10-07T07:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Would Multiple Enterprise Security Splunk Instances Affect Indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/569999#M101044</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239089"&gt;@NightShark&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk best practices hint to use dedicated Search Heads for ES, separated from the other apps SHs.&lt;/P&gt;&lt;P&gt;Indexers are usually shared but obviously the load of ES is usually harder than usual apps becuase there are many accelerated Datamodels and scheduled searches, so you have to design with much attention the resources of your system.&lt;/P&gt;&lt;P data-unlink="true"&gt;So, if you see at&amp;nbsp;https://docs.splunk.com/Documentation/ES/6.6.2/Install/DeploymentPlanning, you need at least (it depends on the indexed logs, scheduled correlation searches and users) 16 CPUs and 32GB of RAM for each Indexer; if you have other apps that use those Indexers you have to give to the Indexers more CPUs and RAMs.&lt;/P&gt;&lt;P data-unlink="true"&gt;Ciao.&lt;/P&gt;&lt;P data-unlink="true"&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 07:52:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/569999#M101044</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-07T07:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Would Multiple Enterprise Security Splunk Instances Affect Indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/570003#M101046</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Giuseppe,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Yes, that is exactly what I was thinking. Is more licensing being used while having ES installed on 3 instances?&lt;/P&gt;&lt;P&gt;So basically having 3 ES Instances also triples the amount of load on the indexers? All the instances are set to high performance recommendations but I was wondering if apart from CPU and RAM load, if it would increase disk usage aswell?&lt;/P&gt;&lt;P&gt;Thank you for the quick response!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 08:00:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/570003#M101046</guid>
      <dc:creator>NightShark</dc:creator>
      <dc:date>2021-10-07T08:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: Would Multiple Enterprise Security Splunk Instances Affect Indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/570006#M101047</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239089"&gt;@NightShark&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand: when you say "Three Es instances" are you speaking of three Search Heads that use the same indexers or three stand alone ESs?&lt;/P&gt;&lt;P&gt;I think that you're speaking of the first choice, in this case you need to exactly designe your reference hardware, taking in consideration:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;all the indexed data (not more than 100 GB/day for each Indexer),&lt;/LI&gt;&lt;LI&gt;the activated Correlation searched and accelerated Datamodels,&lt;/LI&gt;&lt;LI&gt;the users that usually use the system.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Rememeber that this usually is a work for Professional Services or at least for a Splunk Architect, it isn't a job for Community!&lt;/P&gt;&lt;P&gt;If this answer solves your need, please, accept it for the other people of Community, otherwise, tell me how can I help you.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 08:24:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/570006#M101047</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-07T08:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Would Multiple Enterprise Security Splunk Instances Affect Indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/570061#M101050</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for your response, I have forwarded the issue towards Splunk Case to gain further insight.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 13:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/570061#M101050</guid>
      <dc:creator>NightShark</dc:creator>
      <dc:date>2021-10-07T13:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Would Multiple Enterprise Security Splunk Instances Affect Indexing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/570062#M101051</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239089"&gt;@NightShark&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good idea, but I think that they will answer that you have to engage a Splunk Architetct or Professional Services because you haven't a bug.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 13:10:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Would-Multiple-Enterprise-Security-Splunk-Instances-Affect/m-p/570062#M101051</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-07T13:10:16Z</dc:date>
    </item>
  </channel>
</rss>

