Deployment Architecture

Splunk Architecture for huge system

meenal901
Communicator

Hi,

We are starting Splunk on a small environment (2 UF + 1 Indexer) which will eventually be deployed to an huge Production environment as well consisting of over 100 servers (forwarders) and multiple indexers. The data flow would be around 500GB per day (5GB from each forwarder).

Can you help us in planning the architecture for this? What will be the licensing cost considering data filtration almost upto 50%.

Thanks,
Meenal

0 Karma

strive
Influencer

I had a similar question. Check this link
http://answers.splunk.com/answers/126618/hardware-recommendation-for-high-log-volume-splunk-deployme...

I agree with Ayn's answer in this case -- "If you're planning to run Splunk in this kind of high log volume environment you definitely should contact Splunk directly and get in contact with their PS guys who can look at your case more thoroughly"

Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...