Monitoring Splunk

Best practices for building a splunk indexers with local HHD or SSD

benazir
Explorer

Hi ,

our environment collects at least 11 tb of data per day and we have nearly 16 indexers in SAN. we need an advice for the new build ,whether local SSD is powerful in IO rate than SAN?
can we build indexer with local SSD. which is the best practice.

Tags (1)
0 Karma

nickhills
Ultra Champion

If you have an environment that large, I suggest you contact Splunk support for any queries on sizing & performance.

However, the Splunk official sizing guidelines would suggest you would need 110 indexers 🙂
11,000 GB a day \ 100GB per indexer
So at your scale, you are off the official documented charts!

Definitely worth a call to your account manager on that one!

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...