# Splunk sizing with shared core HCI vendors

But I thought *you* checked it!

In recent weeks I've done a fair amount of reading about log management solutions, and I have to say the quality of technical material related to Splunk and Elasticsearch from mainstream vendors is not very good.

Shared-core HCI vendors are worst because not one ever tells you what you're overpaying for - storage, compute, software, or indeed "all of the above"- when you use their "black box" sizing approaches. And when you have no idea what's going on, no sizing can be wrong and your IT budget tends to become their performance bottleneck.

The other problem is their Splunk solution documentation looks superficial and sloppy, which makes you wonder just how much effort went into optimizing these solutions.

![](/assets/images/splunk-sizing-dell-calculation.png)

You'd need more typists than that to manually store data in SmartStore buckets, but Amazon Mechanical Turk may be able to provide sufficient scale and performance for your log archiving needs.

![](/assets/images/splunk-sizing-nutanix-calculation.png)
