Splunk Enterprise Security

How to properly configure a cluster of indexers to work ES?

sh_bolatbekov
New Member

Hello!
We need to implement architecture ES Splunk to 400 GB in clustering (SH, IDX). How we should to count numbers of idx for this capacity? In Splunk docs recommend to use per indexer up to 100Gb. How it will be in IDX clustering? We need data replication on index cluster. How index cluster will replicate 400GB data if Splunk docs recommend to use ES per indexer up to 100Gb?

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You will need at least 4 indexers. Note the "up to 100GB" in the recommendation. That means you may get less throughput per indexer depending on search activity and other factors. I suggest 5 indexers.
Replication mainly affects storage. You'll need more disk space to hold the replicated indexes. See https://splunk-sizing.appspot.com/

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You will need at least 4 indexers. Note the "up to 100GB" in the recommendation. That means you may get less throughput per indexer depending on search activity and other factors. I suggest 5 indexers.
Replication mainly affects storage. You'll need more disk space to hold the replicated indexes. See https://splunk-sizing.appspot.com/

---
If this reply helps you, Karma would be appreciated.
0 Karma

LukeB
Observer

Hello,

can you send me a link for the "up to 100GB" recommendation?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Firstly - please don't dig up threads from four years ago.

Secondly - there's no document specifying "you can ingest 100GB and you'll be fine" since noone will ever give you 100% guarantee. It's a rough estimate assuming some normal conditions using reference indexers. But you might hit your capacity limits way earlier if your search is heavy.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...