How incoming data affects Splunk Enterprise performance
This topic discusses how incoming data impacts indexing performance in Splunk Enterprise.
A reference Splunk Enterprise indexer can index a significant amount of data in a short period of time - over 20 MB of data per second - or over 1700 GB per day. This is if the server is doing nothing else but consuming data.
Performance changes depending on the size and amount of incoming data. Larger events slow down indexing performance. As events increase in size, the indexer uses more system memory to process and index them.
If you need more indexing capacity than a single indexer can provide, you must add indexers into the deployment to account for the increased demand.
Hardware capacity planning for your Splunk Enterprise deployment
How indexed data impacts Splunk Enterprise performance
This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14