Getting Data In

Indexer Sizing

msaleh7422
Engager

We would like your guidance on how to calculate the required number of Splunk indexers for our environment.

Currently, our estimated data ingestion rate is approximately 1 TB per day. We would appreciate it if you could advise on:

  • The recommended number of indexers needed for this ingestion volume

  • I Have multi site deployment
    #splunk
Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

This is the kind of question you go to your local friendly Splunk Partner with, not some randoms on the internet.

There are many factors possibly affecting your environment size and overall architecture - search load, retention, HA requirements...

And if someone here tells you "you need 3 indexers" will you run and issue a procurement order based on this? And what if it happens to be undersized? Or the opposite - it will turn out to be mostly idle and you have paid throught the nose for the hardware?

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @msaleh7422 ,

a quick and dirty evaluation is:

  • one indexer every 200 GB/day og ingestion if you haven't a Premium App (ES or ITSI),
  • one indexer every 100-150 GB/day og ingestion if you have a Premium App (ES or ITSI).

in this second case, in ES training is described to use one indexer every 80 GB/day, but 100-150 GB/day is more correct value.

About CPUs, RAM and storage, you need a Capacity Plan that is very difficoult to do in Community: you need a Splunk Architect from a Splunk Partner.

Ciao.

 Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...