Splunk Enterprise Security

How to properly configure a cluster of indexers to work ES.

New Member

Hello!
We need to implement architecture ES Splunk to 400 GB in clustering (SH, IDX). How we should to count numbers of idx for this capacity? In Splunk docs recommend to use per indexer up to 100Gb. How it will be in IDX clustering? We need data replication on index cluster. How index cluster will replicate 400GB data if Splunk docs recommend to use ES per indexer up to 100Gb?

0 Karma
1 Solution

SplunkTrust
SplunkTrust

You will need at least 4 indexers. Note the "up to 100GB" in the recommendation. That means you may get less throughput per indexer depending on search activity and other factors. I suggest 5 indexers.
Replication mainly affects storage. You'll need more disk space to hold the replicated indexes. See https://splunk-sizing.appspot.com/

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

You will need at least 4 indexers. Note the "up to 100GB" in the recommendation. That means you may get less throughput per indexer depending on search activity and other factors. I suggest 5 indexers.
Replication mainly affects storage. You'll need more disk space to hold the replicated indexes. See https://splunk-sizing.appspot.com/

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma