<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does Splunk SE impact existing infrastructure performance? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-SE-impact-existing-infrastructure-performance/m-p/552198#M9934</link>
    <description>&lt;P&gt;Are you referring to the Security Essentials (SE) app or the Enterprise Security (ES) app?&amp;nbsp; The question mentions the former, but it's in the ES forum.&lt;/P&gt;&lt;P&gt;Neither app ingests any data as they both simply use the data that's already ingested.&lt;/P&gt;&lt;P&gt;There is no specific answer to the question because the performance will depend on how you use the app.&amp;nbsp; The more searches you run the more performance will be impacted.&lt;/P&gt;&lt;P&gt;ES is a known resource hog.&amp;nbsp; That's why Splunk recommends it be installed on a dedicated search head.&lt;/P&gt;&lt;P&gt;As for how to get a better view of the performance situation, use the same techniques you use to monitor the performance of any of your servers.&amp;nbsp; For a more specific answer, ask a more specific question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 May 2021 12:30:22 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-05-19T12:30:22Z</dc:date>
    <item>
      <title>How does Splunk SE impact existing infrastructure performance?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-SE-impact-existing-infrastructure-performance/m-p/552188#M9933</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have been searching for hours but I have yet to come across to an answer to my question:&lt;/P&gt;&lt;P&gt;- How does Splunk SE impact the performance of my existing infrastructure since it will ingest and process a lot of data? (I'm talking CPU performance of switches, virtual machines etc. and general bandwith)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there's a general answer to this question then please let me know. If there's a specific answer to this question and lots more information is needed: Which steps can my organization undertake to get a better view of the performance situation?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 11:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-SE-impact-existing-infrastructure-performance/m-p/552188#M9933</guid>
      <dc:creator>ITAdminBart</dc:creator>
      <dc:date>2021-05-19T11:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk SE impact existing infrastructure performance?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-SE-impact-existing-infrastructure-performance/m-p/552198#M9934</link>
      <description>&lt;P&gt;Are you referring to the Security Essentials (SE) app or the Enterprise Security (ES) app?&amp;nbsp; The question mentions the former, but it's in the ES forum.&lt;/P&gt;&lt;P&gt;Neither app ingests any data as they both simply use the data that's already ingested.&lt;/P&gt;&lt;P&gt;There is no specific answer to the question because the performance will depend on how you use the app.&amp;nbsp; The more searches you run the more performance will be impacted.&lt;/P&gt;&lt;P&gt;ES is a known resource hog.&amp;nbsp; That's why Splunk recommends it be installed on a dedicated search head.&lt;/P&gt;&lt;P&gt;As for how to get a better view of the performance situation, use the same techniques you use to monitor the performance of any of your servers.&amp;nbsp; For a more specific answer, ask a more specific question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 12:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-does-Splunk-SE-impact-existing-infrastructure-performance/m-p/552198#M9934</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-19T12:30:22Z</dc:date>
    </item>
  </channel>
</rss>

