Deployment Architecture

Splunk Index storage configurations

nnimbe1
Path Finder

Hi ,

We are building a new Splunk infrastructure in which daily 300 GB data will be ingested, we are running with 2 indexers in cluster, just want to know what would be the best index storage configuration in indexes.conf.

Like hot,warm,cold storage configurations, i have gone through multiple Splunk documentation but its confusing.

We want to save total of 1 year of logs on disk, in which we need 3 months logs online searchable, and remaining 9 months logs will be on disk(whether it can be compressed if yes then we want 3rd to 6th month logs will be in uncompressed form and from 9th Month to 12th Month logs to be compressed if possible),

Can someone will help with suitable configuration, and what would be the disk space required to storage this logs

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...