How Splunk apps affect Splunk performance
This topic discusses how Splunk apps impact overall Splunk performance on a single reference indexer.
While many apps can run on a single indexer - Splunk actually runs several included with the product - the more things an app does, the more likely you must distribute it across multiple machines.
Many apps require a distributed Splunk deployment by design. Whether it's a case of universal forwarders fetching data and sending it to a single central instance, or many indexers and search heads connected together and serving up reports, dashboards, or alerts, Splunk apps often need more than one server to realize both maximum performance and potential in the enterprise.
How search types impact Splunk performance
How Splunk calculates disk storage
This documentation applies to the following versions of Splunk® Enterprise: 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 5.0.17, 5.0.18