Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
Many data sources, including machine learning and artificial intelligence, are driving unstructured data growth. As unstructured data volumes continue to expand, organizations need visibility into what data exists, where it resides, and how to search, analyze, and visualize it. The unstructured and machine-generated data created by websites, applications, and IoT devices can provide valuable insights throughout the data lifecycle. Cohesity, Splunk, and Cisco work together to combine compute, storage, and analytics at scale, helping organizations unlock greater value from their data.
Cohesity SmartFiles, deployed on Cisco Unified Computing System (UCS), simplifies the management of warm and frozen Splunk data at scale, particularly in Splunk SmartStore-enabled environments. SmartStore decouples compute and storage, enabling indexers to use local storage as a cache for active data while storing the majority of data in a remote object store. Cohesity SmartFiles provides S3-compatible storage that supports this architecture, delivering scalable and efficient data management.
Splunk helps administrators gain operational intelligence from machine data, improving customer service and supporting better business decisions. Events in Splunk are stored as raw, compressed data with indexes that make them searchable, collectively forming the Splunk Enterprise Index, also known as the Indexer.
The Splunk Enterprise Index typically consists of many buckets organized by data age. Splunk stores indexed data in directories called buckets and automatically manages data movement through a policy-driven lifecycle as data ages. This lifecycle is organized into four stages.
Cohesity SmartFiles with Splunk:
Ever-increasing regulatory and industry requirements surrounding data retention mean that enterprises indexing large volumes of data cannot simply rely on default retention processes. Instead, organizations must carefully plan and orchestrate data aging policies based on the bucket stage within the Splunk platform. Customizing the indexer workflow introduces a new challenge for IT teams that rely solely on Splunk for storage: determining where to store data for varying retention periods and how to retrieve it quickly when needed.
Cohesity SmartFiles running on Cisco UCS provides an ideal data management platform for caching hot buckets and offloading warm and frozen buckets, helping maintain low-latency indexing and search performance. As data ages and transitions to frozen stages, organizations can move it to Cohesity SmartFiles on UCS to reduce total cost of ownership (TCO) while freeing valuable resources for active workloads.
SmartFiles addresses long-term storage challenges with a web-scale platform that eliminates siloed infrastructure. IT teams can configure storage paths for each Splunk bucket stage—hot, warm, and frozen—allowing data to be stored in the most appropriate location based on cost, performance, and compliance requirements.
Hot and Warm buckets continue on high-performance primary storage within SmartStore indexers. This gives Splunk administrators full visibility while optimizing storage cost and performance across the data lifecycle. Built on the Cohesity Helios platform, SmartFiles offers globally distributed NFS, SMB, OpenStack Swift, and S3 object storage. Provisioned as “Views,” these volumes leverage capabilities such as scale-out architecture, global variablelength deduplication and compression, and unlimited snapshots and clones.
Cohesity SmartFiles capabilities for storing Splunk buckets:
Capability
Description
Capacity optimization
Globally, variable-length deduplicated data is distributed across all nodes.
Global search
Powerful indexing of all files and object metadata to enable global Google-like search
Quotas
Volumes, file shares, and object buckets
Security
Software-based encryption
Cloud Integration
Native support for Amazon Web Services, Microsoft Azure, and Google Cloud Platform for policy-based archival, tiering, and replication
Finally, as warm data programmatically moves in the Splunk index to the frozen bucket, the data will move to a Cohesity View with low QoS settings, which can still be accessed via S3 endpoints. Splunk uses a cache manager to retrieve noncached buckets from SmartFiles when required for search i.e. data in a frozen bucket cannot be searched and requires manual intervention. Enterprises opting for archival can take advantage of Cohesity CloudArchive for long-term retention and archival to reduce reliance on tape and lower TCO, while also gaining an easy way to retrieve data back on-premises or recover data to a different site.
By combining Cohesity SmartFiles, Splunk, and Cisco UCS, enterprises can uncover more value from all their data while achieving data retention goals and meeting regulatory requirements. Cohesity can also send the alerts and logs to Splunk and thus ensure smooth integration with Cohesity. If your enterprise is already using Splunk, SmartFiles is the ideal complementary storage solution.
3000061-004