Hello,
We are using splunk for our alerting, log collection and performance information on about 80 servers so far. We have about 180 more to go before we are finished setting up the universal forwarders on all of the windows boxes. My question is the hardware layout. Our plan is to use two separate hardware servers for indexers (one indexer per location PA and NY) and use one additional server as a dedicated search head\deployment server.
Is this the best way to set it up for quick searches? Or is there a better way of doing it?
We expect to recieve about 12GB's a day when all is said and done.
Thanks for you advice!!
... View more