Deployment Architecture

Splunk on AWS EC2

garfieldconnoll
Explorer

Hi,

We're working with Splunk on Amazon's EC2 service (Ubuntu).

At the moment we're working off a standard instance, at 10cent per hour.

I was going to upgrade to a high CPU medium instance, at 20cent per hour.

With AWS' announcement today regarding micro instances, I was wondering.....

"Am I better with 1 high CPU medium instance, 2 standard instances, or 10 micro instances?"

Okay, so there's a strong "string L=N, derive N" element to the question. But if I had to choose a route, any suggestions?

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

When in AWS, I would recommend scaling using units of the High-CPU XL instances. It seems like you need less capacity than this, but of the choices, I am pretty sure the 10 micro instances will be unsuitable and clumsy for a typical Splunk workload. I think the Standard Small is also too small, even with two of them, as you are limited to just one core per machine. Between the Standard Large and the High-CPU Large, I might go with the High-CPU, unless you plan to store you indexes on the instance rather than on EBS, in which case the additional space on the Standard might count for more.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

When in AWS, I would recommend scaling using units of the High-CPU XL instances. It seems like you need less capacity than this, but of the choices, I am pretty sure the 10 micro instances will be unsuitable and clumsy for a typical Splunk workload. I think the Standard Small is also too small, even with two of them, as you are limited to just one core per machine. Between the Standard Large and the High-CPU Large, I might go with the High-CPU, unless you plan to store you indexes on the instance rather than on EBS, in which case the additional space on the Standard might count for more.

garfieldconnoll
Explorer

Able to thank gkanapathy's response now, so doing so!

0 Karma

garfieldconnoll
Explorer

Thanks for that. I'd +1 the post, but I don't have permission yet. We don't have a lot of data, but may have a disproportionate number of users for the amount of indexed data. Apologies if I have the 'wrong end of the stick' on that.

Regards,

G.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...