Deployment Architecture

Splunk Index storage configurations

nnimbe1
Path Finder

Hi ,

We are building a new Splunk infrastructure in which daily 300 GB data will be ingested, we are running with 2 indexers in cluster, just want to know what would be the best index storage configuration in indexes.conf.

Like hot,warm,cold storage configurations, i have gone through multiple Splunk documentation but its confusing.

We want to save total of 1 year of logs on disk, in which we need 3 months logs online searchable, and remaining 9 months logs will be on disk(whether it can be compressed if yes then we want 3rd to 6th month logs will be in uncompressed form and from 9th Month to 12th Month logs to be compressed if possible),

Can someone will help with suitable configuration, and what would be the disk space required to storage this logs

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...