Getting Data In

Are performance improvements by splitting a single Splunk instance into one search head and one indexer on their own servers?

getahobby
New Member

Currently, I have a combined instance where the search head and indexer are sitting on the same box. The documentation does indicate that performance improvements will be made by splitting that centralized deployment into one search head and one indexer each on their own servers. (Look at the Summary of Performance Recommendations document) Is that the case? Or do you need to go to one search head with at least two different indexers? Thanks.

0 Karma

Jeremiah
Motivator

How is your current system performing? Look at your cpu, memory, and disk utilization for any constraints. Search heads tend to be cpu/memory bound and indexers tend to be i/o bound. If your current system is not running out of resources, you probably don't need to expand. According to the Performance Recommendations doc:

An indexer that meets the reference hardware requirements can ingest up to 300GB/day while supporting a search load. For a review of the current reference hardware specifications, see "Reference hardware" in this manual.

There is added complexity in managing a multi-server environment. It's not difficult, but if you don't need to switch, stick with a single server. Yes there are probably situations where running a single search head and single indexer will provide some performance advantages, but really, taking that step should be because you plan on expanding past the 300 GB/day mark and will need to add multiple indexers.

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...