Monitoring Splunk

Bandwidth requirements for Splunk

evinasco08
Explorer

hi team

What minimum bandwidth is necessary between indexers and the rest of the platform elements (Heavy Forwarders, Search Heads, Master Cluster, License, Deployment Servers, etc.) for different communications?

Labels (1)
Tags (1)
0 Karma
1 Solution

kiran_panchavat
Influencer
0 Karma

kiran_panchavat
Influencer

@evinasco08 

It truly depends on many factors, like number of events, number of forwarders, as well as stakeholder expectations/requirements, and how much time and money you have!

https://docs.splunk.com/Documentation/Splunk/latest/Capacity/Referencehardware 

https://www.aplura.com/splunk-best-practices/#hardware 

The blog post how's you the bandwidth usage difference between universal and heavy forwarders.

Universal or Heavy, that is the question? | Splunk

The general answer is it depends, however you can refer to

https://answers.splunk.com/answers/2014/what-is-the-minimum-network-bandwidth-required-for-splunk-fo...  OR https://answers.splunk.com/answers/340084/how-to-search-how-much-bandwidth-a-forwarder-is-us.html 

https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Systemrequirements 

https://www.splunk.com/en_us/pdfs/partners/tech-briefs/deploying-splunk-enterprise-on-google-cloud-p... 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...
OSZAR »