Hi Splunkers,
Any reference or benchmark on performance tuning? Gone thorough lot of post on the performance tuning. I am looking for some approximate number of events return per second and server utilization metrics.
Additional information:
Environment : AWS EC2
Splunk version: 6.4.1
Components: 1- SH (32 CPUcore, 2.8ghz, 60 GB ram) , 4 indexer (16 CPU Core, 2.8ghz, 30GB Ram), Index master (16 CPU Core, 2.8ghz, 15GB).
Data size: 100 GB / day
Search factor: 2
Replication factor:2
Disk: 7 TB per indexer /ebs/ gb2 /10,000 iops
Number of events / second : 1,400,000 (Job inspect number of events scanned / seconds)
All the Servers were hardly used 30-40% of CPU and 50-60% ram (based on number of users searching and indexing peak hours). Bandwidth also hardly used. I can see lot of room to improve the performance,,, any help would be much appreciated.
Thanks in advance.
↧