Splunk Enterprise Security

Is it advisable to implement Splunk ES using SmartStore in a 2-site configuration?

elliottj1
New Member

According to https://docs.splunk.com/Documentation/Splunk/8.0.3/Indexer/AboutSmartStore#Current_restrictions_on_S...

"For multisite clusters, if any SmartStore indexes use report acceleration or data model acceleration, you must disable search affinity by setting all search heads to site0."

Since Splunk Enterprise Security uses data model acceleration, would I be ill-advised to implement ES on SmartStore in a 2-site configuration? I'm concerned about performance.

Help with this will be much appreciated!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...