Deployment Architecture

Splunk Sizing

sidtalup27
Explorer

Hello,

We are sizing a Splunk solution for internal usage. Referring to the documentation, it is said that Mid size Indexer will require 48vCPU and 64Gb RAM. However, I wanted to understand how much EPS will this kind of indexer handle.

Please advise

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

That size node should work well for most cases. As @johnhuang said, in pure splunk indexing it should manage 300Gb/d. Then if you have e.g. ES or ITSI then it’s different story.

EPS is dependent of your event size, complexity and what your want to do with them. We should separate EPS for ingestion and search time as those are totally different cases.  Also you should ensure that your storage has at least 800+ (preferred 1200+) IOPS to move data in and out enough quickly. There are couple of tools like Bonnie or fio which you could use to check that.

t. Ismo

0 Karma

johnhuang
Motivator

Here's the sizing recommendation from Splunk: Capacity Planning Manual - Summary of performance recommendations. Your hardware spec should comfortably handle 300GB/day.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...