Splunk® Enterprise

Installation Manual

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Summary of performance recommendations

This topic summarizes the performance recommendations that were given in the performance questionnaire. The table below shows the amount of reference servers that are required to index and search data in Splunk Enterprise, depending on the number of concurrent users and amounts of data that the instance indexes.

As a reminder, the reference hardware is:

  • Intel x86 64-bit chip architecture
  • 2 CPUs, 6 cores per CPU (12 cores total), at least 2 Ghz per core
  • 12 GB RAM
  • Disk subsystem capable of producing 800 IOPS
  • Standard 1Gb Ethernet NIC, optional 2nd NIC for a management network
  • Standard 64-bit Linux or Windows distribution

For additional information about the reference server, read "Reference hardware" in this manual.

Important: The figures shown in the table below only account for the reference server in question performing a single task, such as either indexing or searching. If a server is performing both actions at the same time, performance can and does degrade depending on the amount of indexing and searching happening at the time. The figures shown here are approximate guidelines only.

If you run Splunk apps, have higher indexing volumes, employ multiple or I/O-heavy searches, or need more concurrent users than this table shows, then you should scale your deployment as described in "Hardware capacity planning for a distributed Splunk deployment" in the Distributed Deployment Manual.

If you need more guidance, contact Splunk.

Daily Indexing Volume Number of Concurrent Search Users Recommended Indexers Recommended Search Heads
< 2 GB/day < 2 1, shared N/A
2 GB/day to 250 GB/day up to 4 1, dedicated N/A

Note: For indexing requirements greater than 250 GB per day, or for additional concurrent users, review "Hardware capacity planning for a distributed Splunk deployment" in the Distributed Deployment Manual.

Answers

Have questions? Visit Splunk Answers to see what questions and answers other Splunk users had about hardware and Splunk.

PREVIOUS
Performance questionnaire
  NEXT
Choose the Windows user Splunk Enterprise should run as

This documentation applies to the following versions of Splunk® Enterprise: 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters