<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Specific Splunk Attack Range Resource Specs in Security</title>
    <link>https://community.splunk.com/t5/Security/Specific-Splunk-Attack-Range-Resource-Specs/m-p/744502#M18417</link>
    <description>&lt;P class=""&gt;Hi all,&lt;/P&gt;&lt;P class=""&gt;I’m planning to deploy the Splunk Attack Range in a cloud-based lab environment, likely in AWS or Azure. I need to provide my team with clear guidance on the resource requirements for provisioning multiple virtual machines or instances as part of the full deployment.&lt;/P&gt;&lt;P class=""&gt;From the documentation I see the Attack Range includes: Splunk Enterprise Server,&amp;nbsp; Splunk SOAR, Windows Domain Controller, Windows Server, Windows Workstation, Kali Linux, Nginx server, a general-purpose Linux server, Zeek server, and Snort server (IDS).&lt;/P&gt;&lt;P class=""&gt;I’m looking for recommendations on the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P class=""&gt;Compute — vCPU and RAM requirements for each component when deployed on separate VMs. What instance types have worked well in AWS or Azure?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Storage — Minimum and recommended disk space per instance. Are SSD-backed volumes necessary for performance? What IOPS or throughput is required for log-heavy components like Splunk or Zeek?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Deployment tips — Has anyone successfully deployed this in AWS or Azure? Any suggestions on instance sizing, storage configuration, or common bottlenecks when running all components concurrently?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;Appreciate any best practices or real-world guidance you can share to help with efficient provisioning.&lt;/P&gt;&lt;P class=""&gt;Thanks in advance!&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Apr 2025 17:37:21 GMT</pubDate>
    <dc:creator>branmcd</dc:creator>
    <dc:date>2025-04-18T17:37:21Z</dc:date>
    <item>
      <title>Specific Splunk Attack Range Resource Specs</title>
      <link>https://community.splunk.com/t5/Security/Specific-Splunk-Attack-Range-Resource-Specs/m-p/744502#M18417</link>
      <description>&lt;P class=""&gt;Hi all,&lt;/P&gt;&lt;P class=""&gt;I’m planning to deploy the Splunk Attack Range in a cloud-based lab environment, likely in AWS or Azure. I need to provide my team with clear guidance on the resource requirements for provisioning multiple virtual machines or instances as part of the full deployment.&lt;/P&gt;&lt;P class=""&gt;From the documentation I see the Attack Range includes: Splunk Enterprise Server,&amp;nbsp; Splunk SOAR, Windows Domain Controller, Windows Server, Windows Workstation, Kali Linux, Nginx server, a general-purpose Linux server, Zeek server, and Snort server (IDS).&lt;/P&gt;&lt;P class=""&gt;I’m looking for recommendations on the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P class=""&gt;Compute — vCPU and RAM requirements for each component when deployed on separate VMs. What instance types have worked well in AWS or Azure?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Storage — Minimum and recommended disk space per instance. Are SSD-backed volumes necessary for performance? What IOPS or throughput is required for log-heavy components like Splunk or Zeek?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Deployment tips — Has anyone successfully deployed this in AWS or Azure? Any suggestions on instance sizing, storage configuration, or common bottlenecks when running all components concurrently?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;Appreciate any best practices or real-world guidance you can share to help with efficient provisioning.&lt;/P&gt;&lt;P class=""&gt;Thanks in advance!&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Apr 2025 17:37:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Specific-Splunk-Attack-Range-Resource-Specs/m-p/744502#M18417</guid>
      <dc:creator>branmcd</dc:creator>
      <dc:date>2025-04-18T17:37:21Z</dc:date>
    </item>
  </channel>
</rss>

