Splunk Enterprise

For SmartStore with ES, which requires local disk for 90 days eq. of data, what if our retentn req is total 90 days ?s ?

dm1
Contributor

I am currently working on the architecture design for our Splunk platform in AWS

We have ES and are planning to leverage Smart Store for low cost data retention. I was reading through the pre-reqs of Smart Store. and one of the pre-reqs states, "For SmartStore use with Splunk Enterprise Security, confirm that you have enough local storage available to accommodate 90 days of indexed data, instead of the 30 days otherwise recommended. See Local storage requirements."
 
Now if our data retention requirement itself is a total 90 days worth of data, out of which we are planning to store 50 days worth of data on local fast storage (to save on cost which is the whole idea behind using SS) but if  local disk for 90 days worth of indexed data is mandatory, is it even worth considering S3 ?

Could anyone please help with some advice on this ?
Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

90 days of local cache is not mandatory for ES.  It may, however, be necessary.  It depends on your datamodel accelerations.  By default, many have a summary range of 3 months, which is where the 90-day recommendation comes from.  If you've tuned your datamodels down then you may get away with a smaller cache.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...