I will have 100GB coming in per day, with an expectation of 20 concurrent users at any given time, with probably around 10 overlapping searches. 80% of my searches will be over recent time and quite simple, but some will be over a longer time range and much more complex.
What sort of guidelines can you provide for starting to size my installation?
For hardware sizing, please start with the document: http://www.splunk.com/wiki/Community:Planning_your_Splunk_deployment
We do recommend collaborating with the Splunk sales team for larger deployments.
For hardware sizing, please start with the document: http://www.splunk.com/wiki/Community:Planning_your_Splunk_deployment
We do recommend collaborating with the Splunk sales team for larger deployments.