Great question! Although I have not personally run a production Splunk Enterprise environment using VSAN as the underlying storage, I worked closely with Dell EMC to assess the performance of Splunk Enterprise on VxRail, a hyper-converged solution that uses VSAN as the underlying storage, and can confirm that given proper resource allocation, it meets or exceeds the performance of Splunk's documented reference hardware: http://docs.splunk.com/Documentation/Splunk/6.5.1/Capacity/Referencehardware
I am in the process of working with Dell EMC on a "VxRail Infrastructure for Splunk Enterprise" Solution Guide which includes:
1. Technology overview of Splunk Enterprise and VxRail including Virtual SAN (VSAN).
2. Recommended configurations and best practices for setting up VxRail (including VSAN) for a Splunk Enterprise use case (includes screenshots).
3. Splunk-validated Configurations for VxRail All-Flash for Splunk Enterprise ranging from 50GB/day to 1TB/day.
Note: The sizing guidance in the Splunk-validated Configurations section is for Splunk Enterprise (core only). Apps like Enterprise Security, IT Service Intelligence OR environments that make heavy use of Data Model Acceleration (DMA) and have a large number of saved searches require additional consideration for sizing your Splunk Enterprise deployment.
We're working to get the VxRail solution guide for Splunk Enterprise released as soon as possible. When it's published, it will be linked from the Dell EMC partner page on Splunk's main website (https://www.splunk.com/dellemc). I will also provide an update to this post with the link when it's available.
If there are existing customers running on VxRail or using VSAN for the underlying storage for Splunk Enterprise who would like to share their experiences, we'd love to hear from you! What configuration are you running? What have you found works well? What, if any, problems have you encountered? Sharing is caring!
Thanks and hope this helps! 😃
... View more