Deployment Architecture

Splunk Index storage configurations

nnimbe1
Path Finder

Hi ,

We are building a new Splunk infrastructure in which daily 300 GB data will be ingested, we are running with 2 indexers in cluster, just want to know what would be the best index storage configuration in indexes.conf.

Like hot,warm,cold storage configurations, i have gone through multiple Splunk documentation but its confusing.

We want to save total of 1 year of logs on disk, in which we need 3 months logs online searchable, and remaining 9 months logs will be on disk(whether it can be compressed if yes then we want 3rd to 6th month logs will be in uncompressed form and from 9th Month to 12th Month logs to be compressed if possible),

Can someone will help with suitable configuration, and what would be the disk space required to storage this logs

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...