Splunk Enterprise

Splunk Indexer - how many IOPS expect with this configuration

edoardo_vicendo
Contributor

Hi All,

I know this question is very generic, but I will try asking 🙂

We have 2 sites with this Indexing Tier configuration:

  • Site 01
    • 3 Indexers (dedicated VM with 2x20 physical core CPU Intel Xeon 6148 and 96GB RAM each)
    • SF=2, RF=2
  • Site 02
    • 3 Indexers (dedicated VM with 2x20 physical core CPU Intel Xeon 6148 and 96GB RAM each)
    • SF=2, RF=2

Search Heads are configured with site affinity so searches go on both sites.

Machines are quite new, supposing you don't have any limitation on the storage tier, how many IOPS are you expecting pushing them to the limit?

Thanks a lot,
Edoardo

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If there are no limits on the storage tier then IOPS will be limited by the network.  Since you've not given information about storage, network, or data rate there's no way to offer an IOPS suggestion.

---
If this reply helps you, Karma would be appreciated.

edoardo_vicendo
Contributor

@richgalloway thanks for your feedback

We currently have (per site):

  • HPE Bladesystem using VMware ESXi and RHEL OS
    • 4 Blade
      • Blade 1: 2 SH (2 VM with 20 physical CPU core + 64 GB RAM each)
      • Blade 2: 1 Indexer (dedicated VM with 2x20 physical core CPU + 96GB RAM each)
      • Blade 3: 1 Indexer (dedicated VM with 2x20 physical core CPU + 96GB RAM each)
      • Blade 4: 1 Indexer (dedicated VM with 2x20 physical core CPU + 96GB RAM each)
    • 2 x Fiber Channel Modules 8 ports (each port 16Gb/s)
      • Blade 1-4 connect to 4 ports on Fiber Channel Modules 1 to SAN 1
      • Blade 1-4 connect to 4 ports on Fiber Channel Modules 2 to SAN 2
      • Each Fiber Channel Module is virtualized
    • Storage SAN Hitachi G1000 (All Flash SSD)
      • Each Indexer has a 13TB dedicated LUN (space already reserved)
      • The LUN is mounted as a vmdk

Thanks a lot,

Edoardo

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...