Deployment Architecture

Splunk Architecture for huge system

meenal901
Communicator

Hi,

We are starting Splunk on a small environment (2 UF + 1 Indexer) which will eventually be deployed to an huge Production environment as well consisting of over 100 servers (forwarders) and multiple indexers. The data flow would be around 500GB per day (5GB from each forwarder).

Can you help us in planning the architecture for this? What will be the licensing cost considering data filtration almost upto 50%.

Thanks,
Meenal

0 Karma

strive
Influencer

I had a similar question. Check this link
http://answers.splunk.com/answers/126618/hardware-recommendation-for-high-log-volume-splunk-deployme...

I agree with Ayn's answer in this case -- "If you're planning to run Splunk in this kind of high log volume environment you definitely should contact Splunk directly and get in contact with their PS guys who can look at your case more thoroughly"

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...