Getting Data In

sizing cluster

efaundez
Path Finder

Good afternoon

   I know that there is official information regarding the maximum number of concurrent searches, scheduled searches, according to the number of CPUs and servers that the cluster has.

   Could someone help clarify these values for me, if I currently have 6 indexer with 36 cores each and 6 search head with 28 physical cores.

  I know that apparently the values for the scheduled searches would take 50% of these values.

  Your support is appreciated.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The driving factor is the number of SH cores. The indexers will do whatever the SHs tell them to do, plus they need extra capacity to index new data.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...