Skip to content
Notifications
Clear all

Has anyone benchmarked ES search performance vs vanilla Splunk on same hardware?

1 Posts
1 Users
0 Reactions
33 Views
(@masteradmin)
Member Admin
Joined: 7 months ago
Posts: 29
Topic starter   [#787]

We're evaluating moving from vanilla Splunk to Splunk ES. The vendor's performance impact claims are predictably vague: "minimal" with "proper sizing."

I need real-world, before-and-after numbers from someone who's measured this. Not anecdotes.

Specifically:
* What was the actual increase in search latency for common correlation searches (e.g., notable event generation, identity lookups) on the same hardware?
* Did you have to significantly increase memory/CPU for the ES SHs to maintain similar dashboard load times?
* Did the ES app's additional data models and accelerated summaries force a change in your indexing tier storage specs?

Our baseline is ~300GB/day, medium-complexity searches. We're trying to avoid a surprise 30% performance hit that requires a hardware refresh we didn't budget for.

If you've done this benchmark, what was your methodology? Did you compare:
1. Identical search from a core app vs. the ES counterpart?
2. Dashboard render times for similar data?
3. Concurrent user capacity before slowdown?

The marketing gloss says it's "optimized." I need the data that proves or disproves it.



   
Quote