nerdexam
Splunk

SPLK-2002(205Q) · Question #106

Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)

When architecting a Splunk environment, A, B, and C are the correct sizing parameters. Concurrent users (A) directly drives search head capacity - more simultaneous searches mean more CPU and memory needed on search heads. Data volume (B) is the most fundamental sizing input…

Splunk Capacity Planning and Deployment

Question

Which of the following items are important sizing parameters when architecting a Splunk environment? (select all that apply)

Options

  • ANumber of concurrent users.
  • BVolume of incoming data.
  • CExistence of premium apps.
  • DNumber of indexes.

Explanation

When architecting a Splunk environment, A, B, and C are the correct sizing parameters.

Concurrent users (A) directly drives search head capacity - more simultaneous searches mean more CPU and memory needed on search heads. Data volume (B) is the most fundamental sizing input, determining indexer count, storage capacity, and licensing tier. Premium apps (C) such as Enterprise Security or ITSI impose significant additional resource overhead (dedicated search heads, accelerated data models, elevated memory), so their presence materially changes your hardware footprint.

D (Number of indexes) is a distractor - while index count affects configuration complexity and bucket management, it is not a primary driver of hardware sizing the way data volume or user load is. You can have hundreds of indexes on the same hardware without fundamentally changing your capacity requirements.

Memory tip: Think "U-V-A" - Users, Volume, Apps. These three inputs feed directly into Splunk's official capacity planning calculators. If you're writing a sizing spec, those are the first three questions you answer.

Topics

#capacity planning#sizing#concurrent users#data volume

Community Discussion

No community discussion yet for this question.

Full SPLK-2002(205Q) Practice