Deployment Architecture

Splunk Index storage configurations

nnimbe1
Path Finder

Hi ,

We are building a new Splunk infrastructure in which daily 300 GB data will be ingested, we are running with 2 indexers in cluster, just want to know what would be the best index storage configuration in indexes.conf.

Like hot,warm,cold storage configurations, i have gone through multiple Splunk documentation but its confusing.

We want to save total of 1 year of logs on disk, in which we need 3 months logs online searchable, and remaining 9 months logs will be on disk(whether it can be compressed if yes then we want 3rd to 6th month logs will be in uncompressed form and from 9th Month to 12th Month logs to be compressed if possible),

Can someone will help with suitable configuration, and what would be the disk space required to storage this logs

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...