Splunk POD architecture

Architectural components of the Kubernetes-based Splunk POD environment, including sizing tiers, node types, storage framework, and hardware specifications.

Review the key architectural elements of a Splunk POD deployment, including sizing options, node types, storage framework, and hardware specifications, all of which align with Splunk Validated Architecture (SVA) standards.

Splunk POD sizing options

Splunk POD offers 4 different sizes with NVMe and HDD configurations for each size.

The NVMe configuration uses NVMe storage for indexer, block, and object storage. The HDD configuration uses NVMe storage for indexer and block storage, but uses HDD storage for object storage.

Size Max Ingest Use Case Hardware Profile (nodes)
Small 500 GB/day Department / Small Enterprise 5 nodes, 8 nodes (HDD)
Medium 1 TB/day Mid-size Enterprise 8 nodes, 9 nodes (HDD)
Large 2.5 TB/day Large Enterprise 11 nodes, 15 nodes (HDD)
X-Large 10 TB/day Large Enterprise 21 nodes, 29 nodes (HDD)

For detailed information on Splunk POD sizing options, see Detailed sizing profiles.

For more information on Splunk POD components, see the Splunk POD CVD.

Storage framework

POD uses Ceph to provide block storage and S3-compliant object storage. Ceph block storage supports all components except indexers, and allows pods to reschedule to different nodes without depending on host-local storage. Ceph object storage supports SmartStore and the SOK app framework.

Key features and resiliency

  • Storage isolation: Separates object storage and local storage (on indexers) to prevent resource contention.
  • Data replication: Stores 3 replicas of every object for high availability.
  • Fault tolerance: Withstands simultaneous failure of 2 Ceph nodes.
  • Self-healing: Automatically rebalances data when nodes rejoin the cluster.

Ceph service components

Component Description
MONs (Monitors) Maintain map of cluster state
OSDs (Object Storage Daemon) Handle actual data storage, recovery, replication, and rebalancing
RGW (RADOS Gateway) Provides S3-compatible storage APIs
MGR (Manager) Handles tracking and telemetry
CSI Driver (RBD) Manages mapping, unmapping, attachment, and mounting of block devices to nodes

Storage Mapping

Component Description
SmartStore All warm and cold buckets reside internally in Ceph.
App framework Stores app framework packages in Ceph for distribution across the cluster.
Access control SOK manages Ceph directly with no direct customer access to the internal storage layer.

For more information on Ceph, see the Splunk POD CVD.

Hardware specifications

Cisco Server Model CPU Cores RAM Node role (primary use case)
UCS C225 M8N 48 cores 256 GB Worker (NVMe)
UCS C225 M8N 48 cores 64 GB Reserved Controller
UCS C240 M8L 48 cores 256 GB Worker (HDD)

For detailed hardware specifications, see the Splunk POD CVD.

Component resource allocation (software limits)

SOK enforces these resource constraints per pod:

Pod Type CPU Cores Memory (RAM)
Indexer Pod 36 cores 96 GB
Search Head Pod 24 cores 72 GB
Note: POD deployments that include Enterprise Security (ES) standalone search heads might require additional resources.

Detailed sizing profiles

POD Small

Profile name pod-small
Max Ingest 500 GB/day
Splunk Topology 1 Standalone SH, 3 Clustered IDX, 1 CM, 1 LM
Storage retention Hot data (local cache): 90 days; SmartStore: 1 year
Total Nodes 6 Nodes
C225 Servers 6 (3 Ctrl+Worker, 3 Worker)
Nexus switches 2 Nexus N9K-C9336C-FX2

POD Small (HDD)

Profile name pod-small
Max Ingest 500 GB/day
Splunk Topology 1 Standalone SH, 3 Clustered IDX, 1 CM, 1 LM
Storage retention Hot data (local cache): 90 days; SmartStore: 1 year
Total Nodes 13 Nodes
C225 Servers 4 (3 Ctrl+Worker, 1 Worker)
C240 Servers 4 (4 Workers with HDD)
Nexus switches 2 Nexus N9K-C9336C-FX2

POD Medium

Profile name pod-medium
Max Ingest 1 TB/day
Splunk Topology 3 Clustered SH, 4 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer
Storage retention Hot data (local cache): 90 days; SmartStore: 1 year
Total Nodes 8 Nodes
C225 Servers 8 (3 Ctrl+Worker, 5 Worker)
Nexus switches 2 Nexus N9K-C9336C-FX2

POD Medium(HDD)

Profile name pod-medium
Max Ingest 1 TB/day
Splunk Topology 3 Clustered SH, 4 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer
Storage retention Hot data (local cache): 90 days; SmartStore: 1 year
Total Nodes 9 Nodes
C225 Servers 5 (3 Ctrl+Worker, 2 Worker)
C240 Servers 4 (4 Worker with HDD)
Nexus switches 2 Nexus N9K-C9336C-FX2

POD Large

Profile name pod-large
Max Ingest 2.5 TB/day
Splunk Topology 3 Clustered SH, 5 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer
Storage retention Hot data (local cache): 90 days; SmartStore: 1 year
Total Nodes 11 Nodes
C225 Servers 11 (3 Ctrl+Worker, 8 Worker)
Nexus switches 2 Nexus N9K-C9336C-FX2

POD Large (HDD)

Profile name pod-large
Max Ingest 2.5 TB/day
Splunk Topology 3 Clustered SH, , 5 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployers
Storage retention Hot data (local cache): 90 days; SmartStore: 1 year
Total Nodes 15 Nodes
C225 Servers 6 (3 Ctrl+Worker, 3 Worker)
C240 Servers 9 (Worker with HDD)
Nexus switches 2 Nexus N9K-C9336C-FX2

POD X-Large

Profile name pod-xlarge
Max Ingest 10 TB/day
Splunk Topology 3 Clustered SH, 12 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer
Storage retention Hot data (local cache): 60 days; SmartStore: 180 days
Total Nodes 21 Nodes
C225 Servers 21(3 Ctrl+Worker, 18 Worker)
Nexus switches 2 Nexus N9K-C9336C-FX2

POD X-Large (HDD)

Profile name pod-xlarge
Max Ingest 10 TB/day
Splunk Topology 3 Clustered SH, , 12 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer
Storage retention Hot data (local cache): 60 days; SmartStore: 180 days
Total Nodes 29 Nodes
C225 Servers 13 (3 Ctrl+Worker, 10 Worker)
C245 Servers 16 (16 Worker with HDD)
Nexus switches 4 Nexus N9K-C9336C-FX2
For detailed information on Splunk POD sizing, components, and hardware specifications, see the Splunk POD CVD.