Monitoring Splunk

Best practices for building a splunk indexers with local HHD or SSD


Hi ,

our environment collects at least 11 tb of data per day and we have nearly 16 indexers in SAN. we need an advice for the new build ,whether local SSD is powerful in IO rate than SAN?
can we build indexer with local SSD. which is the best practice.

Tags (1)
0 Karma

Ultra Champion

If you have an environment that large, I suggest you contact Splunk support for any queries on sizing & performance.

However, the Splunk official sizing guidelines would suggest you would need 110 indexers 🙂
11,000 GB a day \ 100GB per indexer
So at your scale, you are off the official documented charts!

Definitely worth a call to your account manager on that one!

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Set Up More Secure Configurations in Splunk Enterprise With Config Assist

This blog post is part 3 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...