the problem
Indexer SSD capacity drives both cost and operational footprint.
Long log retention sits on the most expensive tier in the Splunk stack. Search performance depends on bucket layout. Adding capacity means adding indexers, which means adding licenses and operational work.
- Indexer SSD drives both hardware and licensing cost.
- Long retention sits on the most expensive tier.
- Search performance depends on bucket layout, not just compute.
- Capacity growth forces indexer growth.
the joint solution
SmartStore offloads warm and cold buckets to Scality.
Hot buckets stay on indexer SSD for search performance. Warm and cold buckets move to Scality via S3. Retention scales independently of compute.
- SmartStore offloads warm/cold buckets to Scality.
- Documented 31 → 8 indexers at 1 TB/day.
- Up to 70% total cost reduction documented.
- Four supported deployment patterns.
joint solution benefits
What Splunk on Scality changes.
Free up Tier 1 Splunk storage.
Backups stop wasting expensive indexer-attached storage. Tier 1 returns to analytics, where it earns its cost.
Scale compute and storage independently.
Add indexers for performance, add Scality nodes for capacity. Neither side forces the other to grow.
No RPO/RTO slippage.
Faster backups of Splunk data. Warm and cold buckets don't need a separate backup process. RPO/RTO targets stay met.
Seamless to the Splunk application.
SmartStore is the standard contract. The storage tier behind it stays invisible to operators and analysts.
Joint architecture
How Splunk runs on Scality.
Workloads flow through the partner integration and land on the Scality data layer.


















