Getting Data In

Should we have more servers with less storage or less servers with more storage in an indexer clustering environment?

laytonj76
Explorer

We are in the middle of designing an Integration environment that we ultimately want to replace our Production environment. We have determined sizing based on our daily ingestion, replication, search factor, RAID configuration, etc. The question I have is whether it's recommended to have more servers with less storage or less servers with more storage?

Specifically, if we acquire servers with 12 bays and 2TB drives, we'd need 10 servers. Alternatively, if we acquire servers with 24 bays and 2TB drives we'd need 6 servers. We can support acquisition of either, but is there a recommendation between the two in terms of Splunk performance?

0 Karma

pgreer_splunk
Splunk Employee
Splunk Employee

Sizing is always an "it depends" scenario. Depends on ingest rate, number of concurrent searches, retention policies, etc. etc. etc.

However that said, from an ingest and search stand point, more servers (horizontal expansion) is better than fewer 'bigger' (vertical) expansion/capacity.

There are recommendations on drive size/types from a base I/O perspective - this nifty tool might help when playing around with scenarios.

https://splunk-sizing.appspot.com/

0 Karma

laytonj76
Explorer

Thanks for the response. I forgot to mention the boxes in question will be Indexers.

We used the sizing app and that was very helpful. Our question comes up as the sizing app doesn't have anything that would indicate whether there's an optimal HW configuration (and I'm not sure if this is something it can or should do). In any case, thanks for the response.

I suppose a follow up question is, does splunk scale out well on larger boxes. For example, if Splunk is running on a 14 core server, will it use all 14 cores or is it limited for any particular reason?

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...