Monitoring Splunk

Best practices for building a splunk indexers with local HHD or SSD


Hi ,

our environment collects at least 11 tb of data per day and we have nearly 16 indexers in SAN. we need an advice for the new build ,whether local SSD is powerful in IO rate than SAN?
can we build indexer with local SSD. which is the best practice.

Tags (1)
0 Karma

Ultra Champion

If you have an environment that large, I suggest you contact Splunk support for any queries on sizing & performance.

However, the Splunk official sizing guidelines would suggest you would need 110 indexers 🙂
11,000 GB a day \ 100GB per indexer
So at your scale, you are off the official documented charts!

Definitely worth a call to your account manager on that one!

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...