Deployment Architecture

Splunk Architecture for huge system

meenal901
Communicator

Hi,

We are starting Splunk on a small environment (2 UF + 1 Indexer) which will eventually be deployed to an huge Production environment as well consisting of over 100 servers (forwarders) and multiple indexers. The data flow would be around 500GB per day (5GB from each forwarder).

Can you help us in planning the architecture for this? What will be the licensing cost considering data filtration almost upto 50%.

Thanks,
Meenal

0 Karma

strive
Influencer

I had a similar question. Check this link
http://answers.splunk.com/answers/126618/hardware-recommendation-for-high-log-volume-splunk-deployme...

I agree with Ayn's answer in this case -- "If you're planning to run Splunk in this kind of high log volume environment you definitely should contact Splunk directly and get in contact with their PS guys who can look at your case more thoroughly"

Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...