Deployment Architecture

Search and Federated Search compression ratio

edoardo_vicendo
Builder

Hello,

Supposing you have a Search Head in Cloud, doing Federated Searches to other Search Heads on-prem, which is the compression ratio (if any)?

I have found those useful information about compression between forwarders and Indexers, but not between Search Heads.

 

https://community.splunk.com/t5/Getting-Data-In/What-kind-of-compression-is-used-between-forwarders-...

https://community.splunk.com/t5/Getting-Data-In/Forwarder-Output-Compression-Ratio-what-is-the-expec...

Splunk Cloud Platform Service Details - Splunk Documentation

 

Thanks a lot,

Edoardo

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Compression between Federated Search client and provider is handled by SSL/TLS.

---
If this reply helps you, Karma would be appreciated.

edoardo_vicendo
Builder

Yes I know 🙂

Can we assume the same compression ratio? Or is there any official feedback on that somewhere in the docs?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm not aware of any Splunk documentation on the matter.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...