<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk enterprise sizing with ES in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400586#M173748</link>
    <description>&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;What's your designed Search factor (SF) and Replication factor( RF). Do you have another instance/server acting as 'deployer'? (to manage config for SHC?)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Replication factor =3 since i have 3 SH  and 3 INDXers, Serach head cluster is also 3.&lt;/P&gt;

&lt;H2&gt;I have not added deployer , thanks for info i will add that.I will also be adding deployment server.Will Appreciate if you can mention the recommend specs for both servers.&lt;/H2&gt;

&lt;P&gt;&lt;EM&gt;Have you thought of which correlation searches would you be turning on in the Enterprise Security (ES)? (as this will use concurrent searches in addition to your users, scheduled jobs etc..)&lt;/EM&gt;&lt;/P&gt;

&lt;H2&gt; I have not decided that yet . Need details on that if you can point me to some doc that relates that to hardware sizing.&lt;/H2&gt;

&lt;P&gt;How to account for storage requirement needed for ES data models.&lt;/P&gt;

&lt;H2&gt;I have used same link as mentioned by you , for sizing and it says i  will be needing 30TB storage.&lt;/H2&gt;

&lt;P&gt;Do i need to add additional cores or RAM to indexers or Search heads for Enterprise security application?.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jan 2019 16:44:28 GMT</pubDate>
    <dc:creator>hariskhan</dc:creator>
    <dc:date>2019-01-09T16:44:28Z</dc:date>
    <item>
      <title>Splunk enterprise sizing with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400584#M173746</link>
      <description>&lt;P&gt;Hello everybody,&lt;BR /&gt;
I am sizing hardware for splunk enterprise and enterprise security solution.&lt;BR /&gt;
We are designing that for 80GB/day data for Splunk enterprise and enterprise security and did following hardware sizing for 6  months data retention. We kept in view the HA factor as well.&lt;/P&gt;

&lt;P&gt;Search Heads x3&lt;/P&gt;

&lt;P&gt;Memory  16GB&lt;BR /&gt;&lt;BR /&gt;
Onbox storage:  1TB X 2 Raid 1&lt;BR /&gt;
Processor   8Core X 2 @ 2.1 GHz &lt;BR /&gt;
RAID controller yes &lt;BR /&gt;
Power   AC&lt;BR /&gt;&lt;BR /&gt;
PC  dual    2 port 16GB&lt;/P&gt;

&lt;H1&gt;NIC 1G X4 etnernet&lt;/H1&gt;

&lt;P&gt;Indexersx3&lt;BR /&gt;
Memory  16GB&lt;BR /&gt;
Onbox storage   1TB X 2 Raid 1&lt;BR /&gt;
Processor   8Core X 2 @ 2.1 GHz&lt;BR /&gt;
RAID controller yes&lt;BR /&gt;
Power   AC&lt;BR /&gt;
FC card  dual   2 port 16GB&lt;/P&gt;

&lt;H1&gt;NIC 1G X4 etnernet&lt;/H1&gt;

&lt;P&gt;Master Server   x1&lt;BR /&gt;
Memory  16GB&lt;BR /&gt;&lt;BR /&gt;
Onbox storage 500GB X 2  Raid 1&lt;BR /&gt;
Processor 8Core X 2 @ 2.1GHz&lt;BR /&gt;
RAID controller yes &lt;BR /&gt;
Power AC&lt;BR /&gt;&lt;BR /&gt;
FC card dual    2 port 16GB&lt;/P&gt;

&lt;H1&gt;NIC 1G X4 etnernet&lt;/H1&gt;

&lt;P&gt;Heavy Forwarders x  2&lt;BR /&gt;&lt;BR /&gt;
Memory 16GB &lt;BR /&gt;
Onbox storage 500GB X 2  Raid 1&lt;BR /&gt;
Processor 8Core X 1 @ 2.1GHz&lt;BR /&gt;
Raid Controller yes&lt;BR /&gt;
Power AC  dual  &lt;/P&gt;

&lt;H1&gt;NIC 1G X4 etnernet&lt;/H1&gt;

&lt;P&gt;SAN&lt;/P&gt;

&lt;P&gt;30TB SAN storage with 2 SAN switches. RAID 10 OR 1&lt;/P&gt;

&lt;P&gt;Plan is to make SH cluster and indexer cluster.Master server is also a deployment server.&lt;BR /&gt;
Can someone advice whether above sizing will be adequate for 75GB/day data when used with splunk entperise and enterprise security, In not please advice on any incremental changes?.&lt;BR /&gt;
Can above solution be able to run 4 concurrent searches on dashboard without service deterioration. &lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 05:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400584#M173746</guid>
      <dc:creator>hariskhan</dc:creator>
      <dc:date>2019-01-09T05:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise sizing with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400585#M173747</link>
      <description>&lt;P&gt;What's your designed Search factor (SF) and Replication factor( RF). Do you have another instance/server acting as 'deployer'?  (to manage config for SHC?)&lt;/P&gt;

&lt;P&gt;Have you thought of which correlation searches would you be turning on in the Enterprise Security (ES)? (as this will use concurrent searches in addition to your users, scheduled jobs etc..)&lt;/P&gt;

&lt;P&gt;ES uses datamodels and based on the amount of data which you have in the datamodel acceleration, it will consume additional storage in the indexing tier. that needs to be factored in based on the datamodels planned to be used/correlation searches enabled.&lt;/P&gt;

&lt;P&gt;You can also check this to get a some idea/approach - &lt;A href="https://splunk-sizing.appspot.com/"&gt;https://splunk-sizing.appspot.com/&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 13:05:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400585#M173747</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-01-09T13:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise sizing with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400586#M173748</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;What's your designed Search factor (SF) and Replication factor( RF). Do you have another instance/server acting as 'deployer'? (to manage config for SHC?)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Replication factor =3 since i have 3 SH  and 3 INDXers, Serach head cluster is also 3.&lt;/P&gt;

&lt;H2&gt;I have not added deployer , thanks for info i will add that.I will also be adding deployment server.Will Appreciate if you can mention the recommend specs for both servers.&lt;/H2&gt;

&lt;P&gt;&lt;EM&gt;Have you thought of which correlation searches would you be turning on in the Enterprise Security (ES)? (as this will use concurrent searches in addition to your users, scheduled jobs etc..)&lt;/EM&gt;&lt;/P&gt;

&lt;H2&gt; I have not decided that yet . Need details on that if you can point me to some doc that relates that to hardware sizing.&lt;/H2&gt;

&lt;P&gt;How to account for storage requirement needed for ES data models.&lt;/P&gt;

&lt;H2&gt;I have used same link as mentioned by you , for sizing and it says i  will be needing 30TB storage.&lt;/H2&gt;

&lt;P&gt;Do i need to add additional cores or RAM to indexers or Search heads for Enterprise security application?.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 16:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400586#M173748</guid>
      <dc:creator>hariskhan</dc:creator>
      <dc:date>2019-01-09T16:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise sizing with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400587#M173749</link>
      <description>&lt;P&gt;any update on this ?.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 06:38:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400587#M173749</guid>
      <dc:creator>hariskhan</dc:creator>
      <dc:date>2019-01-11T06:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise sizing with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400588#M173750</link>
      <description>&lt;P&gt;The general rule of thumb for non-clustered Indexers for ES is NO MORE than 100GB/indexer.  I would add 10% indexers if you are going to use clustering.  So you are fine.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2019 01:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400588#M173750</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-12T01:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise sizing with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400589#M173751</link>
      <description>&lt;P&gt;Thanks for the help. &lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2019 03:49:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/400589#M173751</guid>
      <dc:creator>hariskhan</dc:creator>
      <dc:date>2019-01-12T03:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk enterprise sizing with ES</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/643566#M222932</link>
      <description>&lt;P&gt;Hi splunk team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need confirmation, how many sizing that my company need that we will integrate to splunk siem ?&lt;/P&gt;&lt;P&gt;there are 104 source log, with 30 days log retention&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 06:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-enterprise-sizing-with-ES/m-p/643566#M222932</guid>
      <dc:creator>SyaloomKris</dc:creator>
      <dc:date>2023-05-17T06:58:16Z</dc:date>
    </item>
  </channel>
</rss>

