Splunk Search

What are the advantages and disadvantages of placing logs from multiple applications in different indexes?

NatWong
Explorer

Hi,

I am sending logs from multiple applications to SPLUNK. Would appreciate advice on what are the advantages/disadvantages of placing those apps logs in different indexes (i.e. applicationA_index , applicationB_index) as compared to one index.

Thanks in advance gurus !

Tags (1)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

The hard reasons for separate indexes are retention time, maximum index size, and access restrictions.

If two logs end up in the same index, they will...

  • age out at the same time
  • get cleaned up upon occupying the same amount of disk space
  • are searchable by the same roles

A softer reason would be as an additional layer of hierarchy/structure to logically separate your data.
Another softer reason can be performance, for example if you have a very high volume source and a very low volume source. By separating the two you may improve search performance on the low volume source. I wouldn't compromise maintainability for this though unless you observe real issues.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

The hard reasons for separate indexes are retention time, maximum index size, and access restrictions.

If two logs end up in the same index, they will...

  • age out at the same time
  • get cleaned up upon occupying the same amount of disk space
  • are searchable by the same roles

A softer reason would be as an additional layer of hierarchy/structure to logically separate your data.
Another softer reason can be performance, for example if you have a very high volume source and a very low volume source. By separating the two you may improve search performance on the low volume source. I wouldn't compromise maintainability for this though unless you observe real issues.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...