Getting Data In

Indexers hardware

ccuenot
New Member

Hi,

We have planne to install 2 indexers in cluster + 1 VM for search HEAD and 1 VM as master node.
We will start with 50GB/day of indexes data.
We would like to know if someone know the indexer limitation (how many log/by day) on this kind of hardware :
8 core at 2,40Ghz
4 x 8GO RAM
DD Local : 300GB + storage NAS > 1200 IOPS

Thanks by advance.
Chris

Tags (1)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

You probably want to review this: http://docs.splunk.com/Documentation/Splunk/5.0.2/Installation/Systemrequirements#Recommended_hardwa...

Based on those specs, you should be ok on the indexers. Just make sure your VMs have enough CPU and RAM to run searches.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

You will then probably also want to review this: http://docs.splunk.com/Documentation/Splunk/5.0.2/Installation/CapacityplanningforalargerSplunkdeplo.... As long as your VMs can support searching (8 cores and 8 GB RAM), your current configuration should support 50GB/day indexing. The "How many logs" question is answered by "how much" you are indexing. As many logs as it takes to hit 50GB/day.

0 Karma

ccuenot
New Member

Thanks for your answer, but in fact, I would like to know, based on the indexer hardware, the limitation (how many logs is it possible to manage with this hardware) ?

This is a pure capacity planning constraint for a futur usage.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...