Deployment Architecture

Creating multiple indexes

louieb3
Path Finder

I just wanted to check to see how everyone goes about creating indexes. Right now, we seem to be creating a new index for each source that we ingest into splunk. So my question is - are we going about this wrong? Should we be putting more data in main? What are the pros and cons of creating separate indexes vs putting everything together in fewer indexes?

Tags (2)
0 Karma
1 Solution

lukejadamec
Super Champion

If you don't specify an index, then it can increase search time.

If you specify an index, it will reduce search time.

Splunk does not care how many indexes you have, but you might if you cannot easily specify the index that contains the data you're looking for.

View solution in original post

0 Karma

lukejadamec
Super Champion

If you don't specify an index, then it can increase search time.

If you specify an index, it will reduce search time.

Splunk does not care how many indexes you have, but you might if you cannot easily specify the index that contains the data you're looking for.

0 Karma

yannK
Splunk Employee
Splunk Employee

Thousands of indexes is overkill 🙂
from a couple to a dozen of indexes is a good start. all depends of your volume.

Having several indexes is useful for :

  • access control, with permissions role/index
  • retention, to have different size/time retentions per index
  • search performances, by searching on a specific index
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...