As customers add more and more data to Splunk, indexer clusters with large volumes of indexers, indexes, and buckets are becoming commonplace. In Splunk labs we run intensive tests to explore the boundaries of the largest indexer clusters. This session will discuss the lifecycle of a Splunk bucket, why it is a key metric in indexer scalability, and which indicators and tunables to monitor in a very large cluster. We'll also share how we do performance testing, the latest performance results, and best practices for scaling your Splunk Enterprise cluster to 20 million unique buckets and beyond.
Slides PDF link - https://conf.splunk.com/files/2019/slides/FN1635.pdf?podcast=1577146203