Getting Data In

sizing cluster

efaundez
Path Finder

Good afternoon

   I know that there is official information regarding the maximum number of concurrent searches, scheduled searches, according to the number of CPUs and servers that the cluster has.

   Could someone help clarify these values for me, if I currently have 6 indexer with 36 cores each and 6 search head with 28 physical cores.

  I know that apparently the values for the scheduled searches would take 50% of these values.

  Your support is appreciated.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The driving factor is the number of SH cores. The indexers will do whatever the SHs tell them to do, plus they need extra capacity to index new data.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...