Deployment Architecture

Splunk Index storage configurations

nnimbe1
Path Finder

Hi ,

We are building a new Splunk infrastructure in which daily 300 GB data will be ingested, we are running with 2 indexers in cluster, just want to know what would be the best index storage configuration in indexes.conf.

Like hot,warm,cold storage configurations, i have gone through multiple Splunk documentation but its confusing.

We want to save total of 1 year of logs on disk, in which we need 3 months logs online searchable, and remaining 9 months logs will be on disk(whether it can be compressed if yes then we want 3rd to 6th month logs will be in uncompressed form and from 9th Month to 12th Month logs to be compressed if possible),

Can someone will help with suitable configuration, and what would be the disk space required to storage this logs

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...