<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hardware Requirements for 30GB/Day in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Hardware-Requirements-for-30GB-Day/m-p/543855#M18650</link>
    <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;I wanted to clarify one more thing. Our vendor is providing us the CPU with 3.2 GHz, I have reviewed one document for Splunk stating that the requirements is 2 GHz. Will this reduce the amount of required cores?&lt;/P&gt;</description>
    <pubDate>Mon, 15 Mar 2021 12:57:17 GMT</pubDate>
    <dc:creator>rami1918</dc:creator>
    <dc:date>2021-03-15T12:57:17Z</dc:date>
    <item>
      <title>Hardware Requirements for 30GB/Day</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Hardware-Requirements-for-30GB-Day/m-p/543306#M18632</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are planning to move our Splunk environment to our Nutanix infrastructure. We expect our collected logs to be 20-30 GB/Day and Splunk is mainly used as a SIEM solutions where around 4 users are accessing concurrently&lt;/P&gt;&lt;P&gt;We had some internal discussions, and I wanted to understand if we can use less resources than the mentioned below to run Splunk+ES, and if any one is running a similar setup can share the used hardware specs&lt;/P&gt;&lt;P&gt;Search head 24vCPU, 32GB&lt;BR /&gt;ES search head 24vCPU, 32GB&lt;BR /&gt;Indexer 24vCPU, 32GB&lt;BR /&gt;License + Deployment 12vCPU, 16GB&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 05:51:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Hardware-Requirements-for-30GB-Day/m-p/543306#M18632</guid>
      <dc:creator>rami1918</dc:creator>
      <dc:date>2021-03-11T05:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware Requirements for 30GB/Day</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Hardware-Requirements-for-30GB-Day/m-p/543325#M18635</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/197857"&gt;@rami1918&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the minimum requirent6es for Enterprise Security installation is:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Search head&lt;/TD&gt;&lt;TD&gt;16 cores&lt;/TD&gt;&lt;TD&gt;32GB&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Indexer&lt;/TD&gt;&lt;TD&gt;16 cores&lt;/TD&gt;&lt;TD&gt;32GB&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;As you can see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ES/6.5.0/Install/DeploymentPlanning" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.5.0/Install/DeploymentPlanning&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But I hint to use more CPUs especially if you have to enable many scheduled searches, so I think that it's better to use the configuration you proposed.&lt;/P&gt;&lt;P&gt;Eventually you could reduce RAM for the Deployment Server to 12 GB and analyze the Apps to install in the other Search Head to understand if you can reduce something in that installation, but don't reduce ES Search Head and Indexer.&lt;/P&gt;&lt;P&gt;Maintaining the same use of CPUs probably (you can understand this only after the analysis I hinted) it's better to reduce the CPUs and RAM on the first Search Head and put those resources in the ES Search Head and Indexer.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 07:45:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Hardware-Requirements-for-30GB-Day/m-p/543325#M18635</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-11T07:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware Requirements for 30GB/Day</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Hardware-Requirements-for-30GB-Day/m-p/543855#M18650</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;I wanted to clarify one more thing. Our vendor is providing us the CPU with 3.2 GHz, I have reviewed one document for Splunk stating that the requirements is 2 GHz. Will this reduce the amount of required cores?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 12:57:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Hardware-Requirements-for-30GB-Day/m-p/543855#M18650</guid>
      <dc:creator>rami1918</dc:creator>
      <dc:date>2021-03-15T12:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware Requirements for 30GB/Day</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Hardware-Requirements-for-30GB-Day/m-p/543859#M18651</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/197857"&gt;@rami1918&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;No I don't think!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 13:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Hardware-Requirements-for-30GB-Day/m-p/543859#M18651</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-15T13:35:51Z</dc:date>
    </item>
  </channel>
</rss>

