Splunk Enterprise Security

接入日志的最大数量

yafei
New Member

想了解下,SPlunk 单台服务器,最多可以接入多大的数据量 ,可以给工

Labels (1)
0 Karma

meetmshah
Builder

您好,请问一下问题是否已解决,或者您还有其他问题吗?

0 Karma

meetmshah
Builder

你好 @yafei,

Splunk 服务器可以访问的数据没有明确的限制。 例如,如果您有分布式集群/非集群环境,则它可以访问任意数量的事件。 如果询问特定于容量规划,下面是 2 个 Splunk 文档,可以帮助您解决相同问题 -

- https://docs.splunk.com/Documentation/Splunk/9.1.1/Capacity/IntroductiontocapacityplanningforSplunkE...
- https://docs.splunk.com/Documentation/Splunk/9.1.1/Capacity/Referencehardware

另外,这里有一个类似的问题 - https://community.splunk.com/t5/Splunk-Enterprise/Capacity-planning-best-practices-for-Splunk-Enterp...

 

如果有帮助,请接受解决方案并点击 Karma, 或者如果您对此有任何疑问,请告诉我!

0 Karma

yafei
New Member

麻烦提供下,数据规格说明

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...