Getting Data In

Are performance improvements by splitting a single Splunk instance into one search head and one indexer on their own servers?

getahobby
New Member

Currently, I have a combined instance where the search head and indexer are sitting on the same box. The documentation does indicate that performance improvements will be made by splitting that centralized deployment into one search head and one indexer each on their own servers. (Look at the Summary of Performance Recommendations document) Is that the case? Or do you need to go to one search head with at least two different indexers? Thanks.

0 Karma

Jeremiah
Motivator

How is your current system performing? Look at your cpu, memory, and disk utilization for any constraints. Search heads tend to be cpu/memory bound and indexers tend to be i/o bound. If your current system is not running out of resources, you probably don't need to expand. According to the Performance Recommendations doc:

An indexer that meets the reference hardware requirements can ingest up to 300GB/day while supporting a search load. For a review of the current reference hardware specifications, see "Reference hardware" in this manual.

There is added complexity in managing a multi-server environment. It's not difficult, but if you don't need to switch, stick with a single server. Yes there are probably situations where running a single search head and single indexer will provide some performance advantages, but really, taking that step should be because you plan on expanding past the 300 GB/day mark and will need to add multiple indexers.

0 Karma
Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...