Discover the recognizable benefits of deploying Splunk in a cloud-enabled environment based on HPE GreenLake for File Storage.
–By Keith Vanderford, Storage Solutions Engineer, HPE
Splunk deployments typically have a high performance storage tier for hot and warm data, and a cheaper but slower storage tier for cold data. With this implementation, you have to balance search times against capacity constraints. Splunk’s searches are fastest when searching over recent data in your hot and warm buckets. For the best response times, it’s desirable to have all your data on that fastest tier of storage. But the capacity of that tier is usually limited due to the cost of fast flash-based storage. In order to increase capacity while trying to hold total cost down, organizations usually implement a second tier of storage for Splunk’s cold data, using less costly but slower storage technologies. Managing this second tier of storage introduces more complexity to your infrastructure, causing your staff to spend more time administering storage and less time extracting value from the data contained in that storage.
I know you’ve got questions, like:
Shouldn’t my business be more about discovering valuable insights than managing storage?
Why does the second tier of storage for my cold data have to be slower?
Why does storage management have to be complicated?
HPE GreenLake for File Storage provides answers
Here’s good news: With HPE GreenLake for File Storage, your cold storage tier can be fast as well as simple and intuitive to manage.
HPE GreenLake for File Storage provides the perfect infrastructure for a cold storage tier that is both fast and easy to manage. It lets you take advantage of Splunk’s ability to provide the insights you need with fast searches over not just your hot and warm data, but your older (cold) data as well. HPE GreenLake for File Storage is an ultra-efficient all-NVMe storage solution with a cloud-like operational experience for data lakes. It delivers sustained, predictable throughput for enterprise performance at scale. The intuitive cloud interface also helps you reduce operational overhead.
You can reduce the performance penalty normally associated with searching older data by using the fast file-based storage provided by HPE GreenLake for File Storage for Splunk’s cold buckets. Simply mount NFS or SMB file shares provided by the ultra-efficient all-NVMe HPE GreenLake for File Storage solution to your Splunk indexers for cold buckets. These shares can also be used for Splunk’s frozen buckets if you have compliance or archive requirements. With this high performance storage solution, searches over Splunk’s cold buckets are extremely fast, accelerating search response times over traditional implementations that use slower storage for cold data.
The unmatched data reduction and low overhead data protection of HPE GreenLake for File Storage decrease the overall capacity required to store your data. For example, in our internal lab testing the observed data reduction rate has been about 3:1. This is significantly better than the reduction typically achieved for Splunk’s indexed data with most other storage platforms. Low overhead erasure coding is implemented using up to 146 data drives with 4 parity drives. This enables HPE GreenLake for File Storage to provide complete data protection with as little as 3% overhead. The combined benefits of this unique data reduction and low overhead data protection help make the most efficient use of your cold storage tier without slowing down searches over your older data.
How using HPE GreenLake for File Storage with your Splunk deployment makes setup and configuration simple
Creating the SMB or NFS file shares you need is quick and easy, and the self-service console gives you an intuitive cloud experience you can access from anywhere. This empowers you to free up your staff to work on adding value to your business rather than managing the day-to-day operations of your infrastructure.
HPE GreenLake for File Storage is available using a pay-as-you-go pricing model that gives you even more value for your infrastructure investment. You only pay for what you use, without having to pay for excess capacity. More resources are always at the ready to allow you to expand when you need to, but you never have to pay for them until you use them. Thus you can maximize the agility and value of your Splunk storage without the costs associated with overprovisioning.
Free your cold data from a slow storage tier and complicated infrastructure
With Splunk and HPE GreenLake for File Storage, you can have extremely fast searches over older data in your cold data tier, while simplifying the management of your storage. Get faster time to insights, and enable your data analysts and data scientists to unlock more value from your data.
To learn more, read the technical brief: Maximize your Splunk investment with HPE GreenLake for File Storage