Deployment Architecture

What is the appropriate server sizing for Splunk Free on a Red Hat Linux instance running VMWare, 500MB log messaging per day?

ed_hickey
New Member

Running a POC with Splunk. Looking for the appropriate server sizing for a RH Linux instance running on VMWare. Max 500mb per day of log messaging.

Looking for CPU, Memory and Disk.

Thx Ed

Tags (3)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Sizing guides ands installation requirements -
http://docs.splunk.com/Documentation/Splunk/6.1.4/Installation/Systemrequirements http://docs.splunk.com/Documentation/Splunk/6.1.4/Installation/CapacityplanningforalargerSplunkdeplo...

Depending on data sources, but for 500mb/day POC, you can get away with minimal requirements. A 4vcore/4GB ram VM would probably be sufficient. Disk I/o is a contention point depending on what the use case is for your POC.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...