on behalf of the TDAQ collaboration ü The indexing scaled linearly with the number of indexers. ü An indexer had typically ~200% CPU usage. ü The querying scaled linearly with the number of events searched. ü A query running for a long time had typically ~100% CPU usage. ü If CPU utilization is not limited, multiple queries can run simultaneously during the indexing without decreasing the performance. ü When we design a system using Splunk, we need to estimate not only the number of indexer, forwarder and search head, but also the value of the parameter "volume used today" and the actual size of Splunk database increased in a day. If the CPU resource is limited, the number of search run concurrently can be restricted by Splunk configuration. ü If the forwarding rate is too large in average, the data will be overflowed at forwarders, but the sinkhole method or the traffic shaping parameter in the configuration can manage instantaneously high rate or the fluctuation of the rate.