Hello, I've already read the Splunk planning for a large scale deployment documents. However, I didn't get a sense about what would be better for scaling searchheads... adding more servers or adding processors to existing servers. We have a lot of utility hardware and are debating whether we'd get better performance by adding 4 searchheads with 2socket/4core procs, or adding adding 2 searchheads with 4 socket 4 procs, given equal memory/processor speed and ignoring the differences in OS and Hardware Management, does anyone see a PERFORMANCE BASED reason to choose one or the other?
... View more