Hi All,
Good Day, currently our Splunk Infrastructure is built with 3 Heavy Forwarders, 6 Non-clustered Indexers, and 2 Clustered Search Heads, our data sources is huge, our Splunk is currently handling almost 8k+ of log sources (servers, network elements etc.) everyday and is still growing, we almost spent 500 GBs of data every day, and our current license is 600 GB. We are planning to do a migration this year and this is our proposed infrastructure.
2 Deployment Server
12 Heavy Forwarders (per site e.g, Log sources from NewYork site = 2 HFs, Log sources from Canada site = 2 HFs....)
6 Clustered Indexers
2 Clustered Search Heads
I just want to seek recommendations, suggestions etc. Are we doing it right? Thank you for the answers in advance.
Cheers,
Dan
... View more