Splunk Search

If anyone of you or your teams have implemented Splunk in production, kindly share the following details ?

moiezuddin
Explorer
  1. Time taken by splunk to process 200 GB/day (in Hours)? & what is the current volume (log Size) which has been processed by Splunk per day (In Hours)?
  2. Hardware/software details of server in which “splunk server” is running.
0 Karma

skoelpin
SplunkTrust
SplunkTrust

The speed of processing depends on how many cores you have on the indexer along with how many indexers you have indexing the data. It also depends on if you were consuming that data within a 1 hour time frame or if it was distributed over 24 hours. If the latter case then it works very fast.

We currently have 2 clustered indexers with 16 cores each which index around 100-120 GB/day. We have 1 application which has around 5 billion events per month and takes 8 days to process the report on an accelerated data model, so we had to do a workaround and set up a summery index. So my advise is to not to buy tons of hardware for 1-2 applications, there's always a workaround to boost the performance. You also have cloud infrastructure you could leverage if you needed to

0 Karma

renjith_nair
Legend

We have Splunk in production but the amount of data processing depends on your hardware. So it will be different for different environment

If you are looking for the sizing , the following reference should help you.

https://splunk-sizing.appspot.com/
http://docs.splunk.com/Documentation/Splunk/6.2.0/Capacity/Referencehardware
http://docs.splunk.com/Documentation/Splunk/6.2.0/Capacity/Summaryofperformancerecommendations
http://docs.splunk.com/Documentation/Splunk/6.2.0/Capacity/Forwarder-to-indexerratios
http://docs.splunk.com/Documentation/Splunk/6.1/installation/Capacityplanningforalargersplunkdeploym...

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...