Getting Data In

Hard disk requirement for Splunk heavy forwarder

Monica7
New Member

Can you please share the hard disk requirement
for Splunk enterprise and Splunk heavy forwarder

0 Karma

woodcock
Esteemed Legend

What is your use case for HF? Probably you should be using UF. If you are using HF the correct way, then you will not need any special disk space requirements because nothing will be hitting disk and it all will be immediately forwarded to the Indexer Tier.

0 Karma

Monica7
New Member

Hi, In splunk enterprise documentation, It is given like this we need 5 GB of Hard disk for Splunk Enterprise. In the same way ,I need hard disk space requirement for heavy forwarder. I am not able to find in documentation.

Platform Recommended hardware capacity/configuration
Non-Windows platforms 2x six-core, 2+ GHz CPU, 12GB RAM, Redundant Array of Independent Disks (RAID) 0 or 1+0, with a 64 bit OS installed.
Windows platforms 2x six-core, 2+ GHz CPU, 12GB RAM, RAID 0 or 1+0, with a 64-bit OS installed.
RAID 0 disk configurations do not provide fault-tolerance. Confirm that a RAID 0 configuration meets your data reliability needs before deploying a Splunk Enterprise indexer on a system configured with RAID 0.

Maintain a minimum of 5GB of free hard disk space on any Splunk Enterprise instance, including forwarders, in addition to the space required for any indexes. See Estimate your storage requirements in Capacity Planning for a procedure on how to estimate the space you need. Failure to maintain this level of free space can degrade performance and cause operating system failure and data loss.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi Monica7,
if you're speaking of Storage, you have to do a Capacity Planning before define Hard Disks requirements (see Splunk Capacity Planning).
If instead you're speaking of Splunk system hard disks requirements you can see Splunk Hardware requirements.
I cannot access Docs to search paths.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...