How to determine if Splunk needs to be scaled horizontally or vertically? For logs up to 5GB from different inputs, what should be the ideal setup?
up to 5GB dont scale,
stay at a single instance and you will do great
You need to add indexers once you hit about 250GB/day of input.