We would like your guidance on how to calculate the required number of Splunk indexers for our environment.
Currently, our estimated data ingestion rate is approximately 1 TB per day. We would appreciate it if you could advise on:
The recommended number of indexers needed for this ingestion volume
This is the kind of question you go to your local friendly Splunk Partner with, not some randoms on the internet.
There are many factors possibly affecting your environment size and overall architecture - search load, retention, HA requirements...
And if someone here tells you "you need 3 indexers" will you run and issue a procurement order based on this? And what if it happens to be undersized? Or the opposite - it will turn out to be mostly idle and you have paid throught the nose for the hardware?
Hi @msaleh7422 ,
a quick and dirty evaluation is:
in this second case, in ES training is described to use one indexer every 80 GB/day, but 100-150 GB/day is more correct value.
About CPUs, RAM and storage, you need a Capacity Plan that is very difficoult to do in Community: you need a Splunk Architect from a Splunk Partner.
Ciao.
Giuseppe