We're evaluating moving from vanilla Splunk to Splunk ES. The vendor's performance impact claims are predictably vague: "minimal" with "proper sizing."
I need real-world, before-and-after numbers from someone who's measured this. Not anecdotes.
Specifically:
* What was the actual increase in search latency for common correlation searches (e.g., notable event generation, identity lookups) on the same hardware?
* Did you have to significantly increase memory/CPU for the ES SHs to maintain similar dashboard load times?
* Did the ES app's additional data models and accelerated summaries force a change in your indexing tier storage specs?
Our baseline is ~300GB/day, medium-complexity searches. We're trying to avoid a surprise 30% performance hit that requires a hardware refresh we didn't budget for.
If you've done this benchmark, what was your methodology? Did you compare:
1. Identical search from a core app vs. the ES counterpart?
2. Dashboard render times for similar data?
3. Concurrent user capacity before slowdown?
The marketing gloss says it's "optimized." I need the data that proves or disproves it.