Deployment Architecture

Splunk on AWS EC2

garfieldconnoll
Explorer

Hi,

We're working with Splunk on Amazon's EC2 service (Ubuntu).

At the moment we're working off a standard instance, at 10cent per hour.

I was going to upgrade to a high CPU medium instance, at 20cent per hour.

With AWS' announcement today regarding micro instances, I was wondering.....

"Am I better with 1 high CPU medium instance, 2 standard instances, or 10 micro instances?"

Okay, so there's a strong "string L=N, derive N" element to the question. But if I had to choose a route, any suggestions?

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

When in AWS, I would recommend scaling using units of the High-CPU XL instances. It seems like you need less capacity than this, but of the choices, I am pretty sure the 10 micro instances will be unsuitable and clumsy for a typical Splunk workload. I think the Standard Small is also too small, even with two of them, as you are limited to just one core per machine. Between the Standard Large and the High-CPU Large, I might go with the High-CPU, unless you plan to store you indexes on the instance rather than on EBS, in which case the additional space on the Standard might count for more.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

When in AWS, I would recommend scaling using units of the High-CPU XL instances. It seems like you need less capacity than this, but of the choices, I am pretty sure the 10 micro instances will be unsuitable and clumsy for a typical Splunk workload. I think the Standard Small is also too small, even with two of them, as you are limited to just one core per machine. Between the Standard Large and the High-CPU Large, I might go with the High-CPU, unless you plan to store you indexes on the instance rather than on EBS, in which case the additional space on the Standard might count for more.

garfieldconnoll
Explorer

Able to thank gkanapathy's response now, so doing so!

0 Karma

garfieldconnoll
Explorer

Thanks for that. I'd +1 the post, but I don't have permission yet. We don't have a lot of data, but may have a disproportionate number of users for the amount of indexed data. Apologies if I have the 'wrong end of the stick' on that.

Regards,

G.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...