Deployment Architecture

Resource estimation

mahsa_nvd
Loves-to-Learn Lots

Hi everyone,

We're planning a new Splunk deployment and considering three different scenarios (Plan A and B) based on daily ingestion and data retention needs. I would appreciate it if you could review the sizing and let me know if anything looks misaligned or could be optimized based on Splunk best practices.
🔹 Overview of each plan:
Plan A:
Daily ingest: 2.0TB
Retention: same
10 Indexers
3 Search Heads
2 ES Search Heads
CM, MC, SH Deployer, DS, LM, 4–5 HFs, and several UBA/ML nodes
Plan B:
Daily ingest: 2.6TB
Retention: same
13 Indexers
3 Search Heads
3 ES Search Heads
CM, MC, SH Deployer, DS, LM, 4–5 HFs, and several UBA/ML nodes

As I told Each plan includes CM, MC, SH Deployer, DS, LM, 4–5 HFs, and several UBA/ML nodes.

🔹 Example specs per Indexer (Plan C):
Memory: 128GB
vCPU: 96 cores
Disk: 500GB OS SSD + 6TB hot SSD + 30TB cold HDD + 11TB frozen (NAS)
----------------------------------------
🔍 What I'm looking for:
Are these hardware specs reasonable per Splunk sizing guidelines?
Is the number of indexers/search heads appropriate for the daily ingest and retention?
Any red flags or over/under-sizing you would call out?

Thanks in advance for your insights!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, it all depends on your utilization really. The rule of thumb is that a single indexer can handle up to 300GB/day if not running premium apps (ES or ITSI) or 100 GB/day if running ES or ITSI. Actually a single indexer can index way way more daily if it doesn't do any searching. Since you're using ES there's probably gonna be a lot of searching (if not for any other reason, just for keeping datamodel summaries up to date). So one indexer per 200GB might be or not too small, depending on your actual load.

You're pushing quite a lot of hardware for the indexers whereas normally you'd rather want to have more indexers than bigger ones. More CPUs mean you could add ingestion pipelines but - especially if reaching for cold data - you might starve your indexers from I/O performance since you will have potential for many concurrent searches competing for I/O resources.

It's also not clear for me how is this NAS frozen spacd supposed to work. Is it a shared space or do you want to have dedicated share for each indexer? Remember that each indexer freezes buckets independently so unless you script it to keep the storage "tidy" you'll end ul with multiple copies of the same frozen bucket.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...