The reference hardware for a Splunk Search Head (as of Feb 2016) recommends the following:
2 x 300GB, 10,000 RPM SAS hard disks, configured in RAID 1
Will this actually be sufficient for multiple TB/day of data when there are many accelerated searches and summaries? With Search Head clustering?
I'm thinking at least 3 Search Heads for around 3/TB of data/day, but the size of the disks recommended concern me.
I know it's a moving target with a lot of caveats, so how does one approach sizing Search Head disk utlization?
... View more