Splunk Search

Index count on a single Indexer

rashi83
Path Finder

Hi ,

We are running apps in docker world and looking at docker log growth - app / engineering team wants to adapt app + environment level indexing. Meaning each app per environment will have a separate Index. Such that whichever app is misbehaving - it's index will be disabled.
There will be 400 such indexes on single Indexer - is there any kind of performance penalty of having so many Indexes on single Indexer. Indexer is a windows machine - 2 processors 2.40 GHz.
We can add more Indexers if required, but would need to understand capability on a single machine.

Tags (1)
0 Karma

somesoni2
Revered Legend
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...