Splunk® Enterprise

Distributed Deployment Manual

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Summary of performance recommendations

The table below depicts the performance recommendations based on the reference servers described earlier in this chapter. For specifics on those reference servers, read "Reference hardware."

Important: The table shows approximate guidelines only. You should modify these figures based on your specific use case. If you need additional guidance, contact Splunk. You might want to engage a member of Professional Services depending on the deployment's initial size.

Daily Volume Number of Search Users Recommended Indexers Recommended Search Heads
< 2 GB/day < 2 1, shared N/A
2 to 250 GB/day up to 4 1, dedicated N/A
250 to 500 GB/day up to 8 2 N/A
500 to 750 GB/day up to 12 3 1
750 GB to 1 TB/day up to 12 4 1
1 TB to 10 TB/day up to 20 5 to 25 1 to 5
10 TB to 100 TB/day up to 100 25 to 250 5 to 25


Have questions? Visit Splunk Answers to see what questions and answers other users had about hardware and Splunk Enterprise.

How Splunk apps affect resource requirements
Upgrade your distributed environment

This documentation applies to the following versions of Splunk® Enterprise: 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters