Splunk POD architecture
Architectural components of the Kubernetes-based Splunk POD environment, including sizing tiers, node types, storage framework, and hardware specifications.
Review the key architectural elements of a Splunk POD deployment, including sizing options, node types, storage framework, and hardware specifications, all of which align with Splunk Validated Architecture (SVA) standards.
Splunk POD sizing options
Splunk POD offers 4 different sizes with NVMe and HDD configurations for each size.
The NVMe configuration uses NVMe storage for indexer, block, and object storage. The HDD configuration uses NVMe storage for indexer and block storage, but uses HDD storage for object storage.
| Size | Max Ingest | Use Case | Hardware Profile (nodes) |
|---|---|---|---|
| Small | 500 GB/day | Department / Small Enterprise | 5 nodes, 8 nodes (HDD) |
| Medium | 1 TB/day | Mid-size Enterprise | 8 nodes, 9 nodes (HDD) |
| Large | 2.5 TB/day | Large Enterprise | 11 nodes, 15 nodes (HDD) |
| X-Large | 10 TB/day | Large Enterprise | 21 nodes, 29 nodes (HDD) |
For detailed information on Splunk POD sizing options, see Detailed sizing profiles.
For more information on Splunk POD components, see the Splunk POD CVD.
Storage framework
POD uses Ceph to provide block storage and S3-compliant object storage. Ceph block storage supports all components except indexers, and allows pods to reschedule to different nodes without depending on host-local storage. Ceph object storage supports SmartStore and the SOK app framework.
Key features and resiliency
- Storage isolation: Separates object storage and local storage (on indexers) to prevent resource contention.
- Data replication: Stores 3 replicas of every object for high availability.
- Fault tolerance: Withstands simultaneous failure of 2 Ceph nodes.
- Self-healing: Automatically rebalances data when nodes rejoin the cluster.
Ceph service components
| Component | Description |
|---|---|
| MONs (Monitors) | Maintain map of cluster state |
| OSDs (Object Storage Daemon) | Handle actual data storage, recovery, replication, and rebalancing |
| RGW (RADOS Gateway) | Provides S3-compatible storage APIs |
| MGR (Manager) | Handles tracking and telemetry |
| CSI Driver (RBD) | Manages mapping, unmapping, attachment, and mounting of block devices to nodes |
Storage Mapping
| Component | Description |
|---|---|
| SmartStore | All warm and cold buckets reside internally in Ceph. |
| App framework | Stores app framework packages in Ceph for distribution across the cluster. |
| Access control | SOK manages Ceph directly with no direct customer access to the internal storage layer. |
For more information on Ceph, see the Splunk POD CVD.
Hardware specifications
| Cisco Server Model | CPU Cores | RAM | Node role (primary use case) |
|---|---|---|---|
| UCS C225 M8N | 48 cores | 256 GB | Worker (NVMe) |
| UCS C225 M8N | 48 cores | 64 GB | Reserved Controller |
| UCS C240 M8L | 48 cores | 256 GB | Worker (HDD) |
For detailed hardware specifications, see the Splunk POD CVD.
Component resource allocation (software limits)
SOK enforces these resource constraints per pod:
| Pod Type | CPU Cores | Memory (RAM) |
|---|---|---|
| Indexer Pod | 36 cores | 96 GB |
| Search Head Pod | 24 cores | 72 GB |
Detailed sizing profiles
POD Small
| Profile name | pod-small |
| Max Ingest | 500 GB/day |
| Splunk Topology | 1 Standalone SH, 3 Clustered IDX, 1 CM, 1 LM |
| Storage retention | Hot data (local cache): 90 days; SmartStore: 1 year |
| Total Nodes | 6 Nodes |
| C225 Servers | 6 (3 Ctrl+Worker, 3 Worker) |
| Nexus switches | 2 Nexus N9K-C9336C-FX2 |
POD Small (HDD)
| Profile name | pod-small |
| Max Ingest | 500 GB/day |
| Splunk Topology | 1 Standalone SH, 3 Clustered IDX, 1 CM, 1 LM |
| Storage retention | Hot data (local cache): 90 days; SmartStore: 1 year |
| Total Nodes | 13 Nodes |
| C225 Servers | 4 (3 Ctrl+Worker, 1 Worker) |
| C240 Servers | 4 (4 Workers with HDD) |
| Nexus switches | 2 Nexus N9K-C9336C-FX2 |
POD Medium
| Profile name | pod-medium |
| Max Ingest | 1 TB/day |
| Splunk Topology | 3 Clustered SH, 4 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer |
| Storage retention | Hot data (local cache): 90 days; SmartStore: 1 year |
| Total Nodes | 8 Nodes |
| C225 Servers | 8 (3 Ctrl+Worker, 5 Worker) |
| Nexus switches | 2 Nexus N9K-C9336C-FX2 |
POD Medium(HDD)
| Profile name | pod-medium |
| Max Ingest | 1 TB/day |
| Splunk Topology | 3 Clustered SH, 4 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer |
| Storage retention | Hot data (local cache): 90 days; SmartStore: 1 year |
| Total Nodes | 9 Nodes |
| C225 Servers | 5 (3 Ctrl+Worker, 2 Worker) |
| C240 Servers | 4 (4 Worker with HDD) |
| Nexus switches | 2 Nexus N9K-C9336C-FX2 |
POD Large
| Profile name | pod-large |
| Max Ingest | 2.5 TB/day |
| Splunk Topology | 3 Clustered SH, 5 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer |
| Storage retention | Hot data (local cache): 90 days; SmartStore: 1 year |
| Total Nodes | 11 Nodes |
| C225 Servers | 11 (3 Ctrl+Worker, 8 Worker) |
| Nexus switches | 2 Nexus N9K-C9336C-FX2 |
POD Large (HDD)
| Profile name | pod-large |
| Max Ingest | 2.5 TB/day |
| Splunk Topology | 3 Clustered SH, , 5 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployers |
| Storage retention | Hot data (local cache): 90 days; SmartStore: 1 year |
| Total Nodes | 15 Nodes |
| C225 Servers | 6 (3 Ctrl+Worker, 3 Worker) |
| C240 Servers | 9 (Worker with HDD) |
| Nexus switches | 2 Nexus N9K-C9336C-FX2 |
POD X-Large
| Profile name | pod-xlarge |
| Max Ingest | 10 TB/day |
| Splunk Topology | 3 Clustered SH, 12 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer |
| Storage retention | Hot data (local cache): 60 days; SmartStore: 180 days |
| Total Nodes | 21 Nodes |
| C225 Servers | 21(3 Ctrl+Worker, 18 Worker) |
| Nexus switches | 2 Nexus N9K-C9336C-FX2 |
POD X-Large (HDD)
| Profile name | pod-xlarge |
| Max Ingest | 10 TB/day |
| Splunk Topology | 3 Clustered SH, , 12 Clustered IDX, 1 CM, 1 LM, 1 SHC Deployer |
| Storage retention | Hot data (local cache): 60 days; SmartStore: 180 days |
| Total Nodes | 29 Nodes |
| C225 Servers | 13 (3 Ctrl+Worker, 10 Worker) |
| C245 Servers | 16 (16 Worker with HDD) |
| Nexus switches | 4 Nexus N9K-C9336C-FX2 |