Deployment Architecture

Splunk on AWS EC2

garfieldconnoll
Explorer

Hi,

We're working with Splunk on Amazon's EC2 service (Ubuntu).

At the moment we're working off a standard instance, at 10cent per hour.

I was going to upgrade to a high CPU medium instance, at 20cent per hour.

With AWS' announcement today regarding micro instances, I was wondering.....

"Am I better with 1 high CPU medium instance, 2 standard instances, or 10 micro instances?"

Okay, so there's a strong "string L=N, derive N" element to the question. But if I had to choose a route, any suggestions?

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

When in AWS, I would recommend scaling using units of the High-CPU XL instances. It seems like you need less capacity than this, but of the choices, I am pretty sure the 10 micro instances will be unsuitable and clumsy for a typical Splunk workload. I think the Standard Small is also too small, even with two of them, as you are limited to just one core per machine. Between the Standard Large and the High-CPU Large, I might go with the High-CPU, unless you plan to store you indexes on the instance rather than on EBS, in which case the additional space on the Standard might count for more.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

When in AWS, I would recommend scaling using units of the High-CPU XL instances. It seems like you need less capacity than this, but of the choices, I am pretty sure the 10 micro instances will be unsuitable and clumsy for a typical Splunk workload. I think the Standard Small is also too small, even with two of them, as you are limited to just one core per machine. Between the Standard Large and the High-CPU Large, I might go with the High-CPU, unless you plan to store you indexes on the instance rather than on EBS, in which case the additional space on the Standard might count for more.

garfieldconnoll
Explorer

Able to thank gkanapathy's response now, so doing so!

0 Karma

garfieldconnoll
Explorer

Thanks for that. I'd +1 the post, but I don't have permission yet. We don't have a lot of data, but may have a disproportionate number of users for the amount of indexed data. Apologies if I have the 'wrong end of the stick' on that.

Regards,

G.

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...