Getting Data In

Are performance improvements by splitting a single Splunk instance into one search head and one indexer on their own servers?

getahobby
New Member

Currently, I have a combined instance where the search head and indexer are sitting on the same box. The documentation does indicate that performance improvements will be made by splitting that centralized deployment into one search head and one indexer each on their own servers. (Look at the Summary of Performance Recommendations document) Is that the case? Or do you need to go to one search head with at least two different indexers? Thanks.

0 Karma

Jeremiah
Motivator

How is your current system performing? Look at your cpu, memory, and disk utilization for any constraints. Search heads tend to be cpu/memory bound and indexers tend to be i/o bound. If your current system is not running out of resources, you probably don't need to expand. According to the Performance Recommendations doc:

An indexer that meets the reference hardware requirements can ingest up to 300GB/day while supporting a search load. For a review of the current reference hardware specifications, see "Reference hardware" in this manual.

There is added complexity in managing a multi-server environment. It's not difficult, but if you don't need to switch, stick with a single server. Yes there are probably situations where running a single search head and single indexer will provide some performance advantages, but really, taking that step should be because you plan on expanding past the 300 GB/day mark and will need to add multiple indexers.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...