All Apps and Add-ons

Since Splunk does not have a central database, how does it hold historical data?

aracnacon
New Member

We currently use SCOM for Hostorical Data and we are considering using Splunk. Since Splunk does not have a central database how does it hold Historical Data, such as a years worth of data?

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Splunk holds its data in a proprietary file "database", structured smartly for efficient searches. In larger deployments, Splunk scales horizontally with many Splunk Indexer instances, each holding a fraction of the data (and potentially replicated copies...).

Here's one way of approaching the docs to understand scaling Splunk for lots of data: http://docs.splunk.com/Documentation/Splunk/6.2.4/Deploy/Distributedoverview

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Splunk holds its data in a proprietary file "database", structured smartly for efficient searches. In larger deployments, Splunk scales horizontally with many Splunk Indexer instances, each holding a fraction of the data (and potentially replicated copies...).

Here's one way of approaching the docs to understand scaling Splunk for lots of data: http://docs.splunk.com/Documentation/Splunk/6.2.4/Deploy/Distributedoverview

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...