Deployment Architecture

Splunk Architecture for huge system

meenal901
Communicator

Hi,

We are starting Splunk on a small environment (2 UF + 1 Indexer) which will eventually be deployed to an huge Production environment as well consisting of over 100 servers (forwarders) and multiple indexers. The data flow would be around 500GB per day (5GB from each forwarder).

Can you help us in planning the architecture for this? What will be the licensing cost considering data filtration almost upto 50%.

Thanks,
Meenal

0 Karma

strive
Influencer

I had a similar question. Check this link
http://answers.splunk.com/answers/126618/hardware-recommendation-for-high-log-volume-splunk-deployme...

I agree with Ayn's answer in this case -- "If you're planning to run Splunk in this kind of high log volume environment you definitely should contact Splunk directly and get in contact with their PS guys who can look at your case more thoroughly"

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...