I'm planning on deploying a Splunk infrastructure.
I'm currently undecided whether I should build the infrastructure according to the following configurations.
Multisite-Cluster hosted across two data centers with one ESX Server each
Bare Metal Virtualization
1 Master Node residing on only one of the data centers
1 Search Head for each data center (hosted on ESX)
1 Indexer for each datacenter (hosted on ESX) OR
2 Indexers for each datacenter (hosted on ESX)
With 1 indexer on each site, I planned to have a replication factor of 2 and a search factor of 2 and a site-rep-factor of 1.
With 2 indexers on each site a replication factor of 4 and a search factor of 3 and a site-rep-factor of 2.
Is it advisable to host 2 smaller indexers instead of one big indexer?
Are there performance benefits or caveats?