All Apps and Add-ons

Since Splunk does not have a central database, how does it hold historical data?

aracnacon
New Member

We currently use SCOM for Hostorical Data and we are considering using Splunk. Since Splunk does not have a central database how does it hold Historical Data, such as a years worth of data?

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Splunk holds its data in a proprietary file "database", structured smartly for efficient searches. In larger deployments, Splunk scales horizontally with many Splunk Indexer instances, each holding a fraction of the data (and potentially replicated copies...).

Here's one way of approaching the docs to understand scaling Splunk for lots of data: http://docs.splunk.com/Documentation/Splunk/6.2.4/Deploy/Distributedoverview

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Splunk holds its data in a proprietary file "database", structured smartly for efficient searches. In larger deployments, Splunk scales horizontally with many Splunk Indexer instances, each holding a fraction of the data (and potentially replicated copies...).

Here's one way of approaching the docs to understand scaling Splunk for lots of data: http://docs.splunk.com/Documentation/Splunk/6.2.4/Deploy/Distributedoverview

Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...