All Apps and Add-ons
Highlighted

Since Splunk does not have a central database, how does it hold historical data?

New Member

We currently use SCOM for Hostorical Data and we are considering using Splunk. Since Splunk does not have a central database how does it hold Historical Data, such as a years worth of data?

Tags (2)
0 Karma
Highlighted

Re: Since Splunk does not have a central database, how does it hold historical data?

SplunkTrust
SplunkTrust

Splunk holds its data in a proprietary file "database", structured smartly for efficient searches. In larger deployments, Splunk scales horizontally with many Splunk Indexer instances, each holding a fraction of the data (and potentially replicated copies...).

Here's one way of approaching the docs to understand scaling Splunk for lots of data: http://docs.splunk.com/Documentation/Splunk/6.2.4/Deploy/Distributedoverview

View solution in original post

Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.