<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Specification for web server in Security</title>
    <link>https://community.splunk.com/t5/Security/Specification-for-web-server/m-p/50840#M1664</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We are planning to deploy the web service on a dedicated server, can you please let me know the recommended hardware specification?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;

&lt;P&gt;David&lt;/P&gt;</description>
    <pubDate>Sun, 27 Feb 2011 18:00:41 GMT</pubDate>
    <dc:creator>davidxinli</dc:creator>
    <dc:date>2011-02-27T18:00:41Z</dc:date>
    <item>
      <title>Specification for web server</title>
      <link>https://community.splunk.com/t5/Security/Specification-for-web-server/m-p/50840#M1664</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We are planning to deploy the web service on a dedicated server, can you please let me know the recommended hardware specification?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;

&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Sun, 27 Feb 2011 18:00:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Specification-for-web-server/m-p/50840#M1664</guid>
      <dc:creator>davidxinli</dc:creator>
      <dc:date>2011-02-27T18:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Specification for web server</title>
      <link>https://community.splunk.com/t5/Security/Specification-for-web-server/m-p/50841#M1665</link>
      <description>&lt;P&gt;Just to be clear, the web service still needs a full installation of Splunk, though it would not necessarily perform any indexing. What you're looking for is a dedicated &lt;A href="http://www.splunk.com/base/Documentation/4.1.7/Admin/Installadedicatedsearchhead" rel="nofollow"&gt;search head&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;To get started, look here:
&lt;A href="http://www.splunk.com/base/Documentation/4.1.7/Installation/CapacityplanningforalargerSplunkdeployment#Dividing_up_indexing_and_searching" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.7/Installation/CapacityplanningforalargerSplunkdeployment#Dividing_up_indexing_and_searching&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In broad terms, shoot for at least one core per concurrent user, plus another one or two for scheduled search jobs.  CPU and RAM will be considerably more important than disk.  (Most of the disk load is on indexers, not search heads).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2011 06:21:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Specification-for-web-server/m-p/50841#M1665</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2011-02-28T06:21:00Z</dc:date>
    </item>
  </channel>
</rss>

