Splunk Enterprise

For SmartStore with ES, which requires local disk for 90 days eq. of data, what if our retentn req is total 90 days ?s ?

dm1
Contributor

I am currently working on the architecture design for our Splunk platform in AWS

We have ES and are planning to leverage Smart Store for low cost data retention. I was reading through the pre-reqs of Smart Store. and one of the pre-reqs states, "For SmartStore use with Splunk Enterprise Security, confirm that you have enough local storage available to accommodate 90 days of indexed data, instead of the 30 days otherwise recommended. See Local storage requirements."
 
Now if our data retention requirement itself is a total 90 days worth of data, out of which we are planning to store 50 days worth of data on local fast storage (to save on cost which is the whole idea behind using SS) but if  local disk for 90 days worth of indexed data is mandatory, is it even worth considering S3 ?

Could anyone please help with some advice on this ?
Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

90 days of local cache is not mandatory for ES.  It may, however, be necessary.  It depends on your datamodel accelerations.  By default, many have a summary range of 3 months, which is where the 90-day recommendation comes from.  If you've tuned your datamodels down then you may get away with a smaller cache.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...