Splunk® Enterprise

Capacity Planning Manual

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Summary of performance recommendations

The Daily Indexing Volume table summarizes the performance recommendations that were given in the performance checklist. The table shows the number of reference machines that you need to index and search data in Splunk Enterprise, depending on the number of concurrent users and the amounts of data that the instance indexes.

See "Reference hardware" in this manual for a reminder of what the current reference machine is.

The table shows approximate guidelines only. Modify these figures based on your use case. If you need help, contact Splunk. You might want to engage a member of Professional Services depending on the deployment's initial size.


Daily Indexing Volume
< 2GB/day 2 to 250 GB/day 250 to 500 GB/day 500 to 750 GB/day 750GB to 1 TB/day 1 to 2TB/day 2 to 3TB/Day
Total Users: less than 4 1 combined instance 1 combined instance
1 Search Head
2 Indexers
1 Search Head
3 Indexers
1 Search Head
4 Indexers
1 Search Head
8 Indexers
1 Search Head
12 Indexers
Total Users: up to 8 1 combined instance
1 Search Head
1 Indexer
1 Search Head
2 Indexers
1 Search Head
4 Indexers
1 Search Head
5 Indexers
1 Search Head
10 Indexers
1 Search Head
15 Indexers
Total Users: up to 16
1 Search Head
1 Indexer
1 Search Head
1 Indexer
1 Search Head
3 Indexers
1 Search Head
4 Indexers
2 Search Heads
6 Indexers
2 Search Heads
12 Indexers
2 Search Heads
18 Indexers
Total Users: up to 24
1 Search Head
1 Indexer
1 Search Head
2 Indexers
2 Search Heads
3 Indexers
2 Search Heads
4 Indexers
2 Search Heads
6 Indexers
2 Search Heads
12 Indexers
2 Search Heads
18 Indexers
Total Users: up to 48
1 Search Head
2 Indexer
2 Search Heads
3 Indexers
2 Search Heads
4 Indexers
3 Search Heads
8 Indexers
3 Search Heads
16 Indexers
3 Search Heads
24 Indexers

Answers

Have questions? Visit Splunk Answers to see what questions and answers other users had about hardware and Splunk Enterprise.

PREVIOUS
Performance checklist
  NEXT
Forwarder-to-indexer ratios

This documentation applies to the following versions of Splunk® Enterprise: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters