Hiya
Thinking of using Splunk but worry Splunk takes too much PC resources if use it directly on the servers where the critical applications are running. Any concern at all? Or we should copy the files out to another server/or NAS etc and use Splunk there ??
Many thanks.
Personally, I would recommend keeping your indexer on its own server. Our Splunk indexer is very memory and CPU intensive, so much so that it could interfere with other running applications.
We put SplunkLightForwarders on our application servers and simply have the logs forwarded to the indexer.