Splunk Enterprise

Splunk Architecture, How do we know we need how many Search Heads and Indexers.

Rocky31
Path Finder

We have like 5 S.H and 7 Indexers, how i know these numbers, some environments have 10 indexers and more SH, how we will know we need that number,

If anyone understood my question and answers me i will be very thankful to you.

0 Karma
1 Solution

asimagu
Builder

Feel free to play with this tool: https://splunk-sizing.appspot.com/

Besides that, answering your question about your need is not a simple task as it may require a full architecture analysis for the ideal solution

View solution in original post

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

We have a document that can provide general guidance based on our Reference Hardware:

Jacob
Sr. Technical Support Engineer

adonio
Ultra Champion

can you kindly elaborate?
how much data do you index every day? how many users do you have? how many concurrent searches? are your indexers clustered? are your search heads clustered?

Rocky31
Path Finder

Thank for your response, here i want to know how we will figure out, how many SH, indexers we required for our environment. PLEASE TRY TO UNDERSTAND I AM VERY NEW TO THIS TOOL.

0 Karma

asimagu
Builder

Feel free to play with this tool: https://splunk-sizing.appspot.com/

Besides that, answering your question about your need is not a simple task as it may require a full architecture analysis for the ideal solution

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...