Making a design decision
By now, you should be fairly convinced that unless you are planning a small Splunk Enterprise deployment on a single stand-alone server, or perhaps several stand-alone indexers for point-solutions with a single search head to search across all of them, you will need to design a distributed, clustered environment that provides higher reliability and scalability.
Remember that a distributed/clustered Splunk environment can be scaled as needed by adding additional indexers and/or search heads, and you should assume that there is going to be some amount of growth over time; you may also find that your ingestion volume shortly after initial turn-up exceeds the volumes your business units tell you about, and the peak concurrent ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access