- Community Home
- >
- Storage
- >
- HPE Nimble Storage
- >
- Application Integration
- >
- Splunk / Logstash on Nimble Storage
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-03-2014 10:21 AM
09-03-2014 10:21 AM
We are currently considering moving a splunk indexer onto our CS460. I'm curious as to whether any other customers have deployed log indexing services such as splunk or logstash on Nimble, and what kind of recommendations you might have in terms of configuration, performance policies, etc.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-03-2014 12:47 PM
09-03-2014 12:47 PM
SolutionHello Casey,
Yes we absolutely do have a few customers who have chosen Nimble for their Splunk deployment (one being a pretty large Telco in the US no less). There's no Best Practice Guide for this deployment yet - but the first step is being certified for Splunk which happened a couple of weeks ago.
From what i've heard internally we've got some deployments with Indexers and Searchers on the Nimble platform, and some with just Searchers (Indexing being done on the host side).
Here's some notes taken from an internal discussion on the subject recently:
- Splunk IO patterns will vary depending on the use case but there are basically two types of IO. If there is a lot of search, then a lot of random read IO. If there is little search and just archive – then lots of larger sequential write IO for Index. So the answer is..it depends but both will be present. It may be better to separate the Index and Search functions. They will be on separate servers.
- Search heads can be virtualized (VMware Performance policy) and Index servers will generally be Physical per Splunk best practices (so a custom policy with 32k block size) for the index volume(s). Aggressive Caching may be applicable to the Indexing servers so may need bigger SSDs or an All Flash Shelf.
- The real cool thing with Nimble is that we can transparently handle both forms of workloads within Splunk using CASLs intelligence, unlike an Flash Only (aka All Flash Array) which will not be good for the Index function. Adaptive Flash in action
- We will get some compression on top of Splunk’s (zlib) in the Index - somewhere in the region of 20-30%.
Hope this helps!
twitter: @nick_dyer_