<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Architecture for Production in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Architecture-for-Production/m-p/191308#M38074</link>
    <description>&lt;P&gt;Hi, &lt;BR /&gt;
 We have 140 production servers, where we are planning to install universal forwarders.&lt;BR /&gt;
Further we need to do processing to filter out data and send around 50 perc data to the indexers.&lt;BR /&gt;
Each production server is producing around 1.5 GB of data . &lt;/P&gt;

&lt;P&gt;With this much data volume and server count. What should be the number of heavy forwarders, indexers and search heads we should be using.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Aug 2014 05:50:16 GMT</pubDate>
    <dc:creator>meenal901</dc:creator>
    <dc:date>2014-08-22T05:50:16Z</dc:date>
    <item>
      <title>Splunk Architecture for Production</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Architecture-for-Production/m-p/191308#M38074</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;
 We have 140 production servers, where we are planning to install universal forwarders.&lt;BR /&gt;
Further we need to do processing to filter out data and send around 50 perc data to the indexers.&lt;BR /&gt;
Each production server is producing around 1.5 GB of data . &lt;/P&gt;

&lt;P&gt;With this much data volume and server count. What should be the number of heavy forwarders, indexers and search heads we should be using.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2014 05:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Architecture-for-Production/m-p/191308#M38074</guid>
      <dc:creator>meenal901</dc:creator>
      <dc:date>2014-08-22T05:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Architecture for Production</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Architecture-for-Production/m-p/191309#M38075</link>
      <description>&lt;P&gt;Hi meenal901,&lt;/P&gt;

&lt;P&gt;this cannot be answered here; it all depends on your existing infrastructure, your use cases and other requirements like how many concurrent search will run, do you depend on live near real-time data and so on. &lt;/P&gt;

&lt;P&gt;As a rule of thumb take a look at the docs about &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Installation/Systemrequirements#Recommended_hardware"&gt;recommended hardware&lt;/A&gt; which should be good to index about 100Gb/day.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2014 06:06:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Architecture-for-Production/m-p/191309#M38075</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-08-22T06:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Architecture for Production</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Architecture-for-Production/m-p/191310#M38076</link>
      <description>&lt;P&gt;Additionally, the effort to perform the 50% filtering you mentioned depends heavily on how the filters are built. Very simple filters won't have a huge impact while complex (badly built, usually) filters can make your servers grind to a halt.&lt;BR /&gt;
Therefore it's impossible to say based on just a few numbers how many HFs you need, whether it'd make sense to use HFs at the sources instead of UFs, whether it'd make sense to send 100% to the indexers and filter there (network? legal issues?), and so on.&lt;/P&gt;

&lt;P&gt;Schedule a workshop with your local Splunk Partner or Splunk Sales Engineer.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2014 09:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Architecture-for-Production/m-p/191310#M38076</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-08-22T09:20:40Z</dc:date>
    </item>
  </channel>
</rss>

