<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hardware requirement for intermediate forwarder server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549952#M91334</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233999"&gt;@Thang_TV&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;there isn't an explicit hardware reference for Heavy Forwarders, this means that (to be sure) you should take the hardware reference for a stand alone Splunk Server: 12 CPUs and 12 GB RAM.&lt;/P&gt;&lt;P&gt;If you have availabilità it's better to give these resources to your virtual machine.&lt;/P&gt;&lt;P&gt;If instead you haven't availability and you analyzed that you haven't an hard work for it, you could try with 8 CPUs and 8 GB RAM, monitoring it to understand if it reach to do its work.&lt;/P&gt;&lt;P&gt;The thing to analyze are: log parsing and eventual management of external syslog output queue.&lt;/P&gt;&lt;P&gt;In my experince, usually it's sufficient and I always start with these resources; only one time I had to give more resources because I saw that the HF was in trouble (slow queues) to do a very hard work: receive logs from some Universal Forwarders and syslogs from some appliances, parse them, manage an output syslog queue very large.&lt;/P&gt;&lt;P&gt;About hard disks, it's an intermediate Forwarder without local indexing, you can give 30 GB, or (better) 50.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 30 Apr 2021 05:29:56 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-04-30T05:29:56Z</dc:date>
    <item>
      <title>Hardware requirement for intermediate forwarder server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549949#M91333</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I want to know hardware requirement for intermediate forwarder server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;CPU, DISK, RAM.&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 03:52:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549949#M91333</guid>
      <dc:creator>Thang_TV</dc:creator>
      <dc:date>2021-04-30T03:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware requirement for intermediate forwarder server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549952#M91334</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233999"&gt;@Thang_TV&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;there isn't an explicit hardware reference for Heavy Forwarders, this means that (to be sure) you should take the hardware reference for a stand alone Splunk Server: 12 CPUs and 12 GB RAM.&lt;/P&gt;&lt;P&gt;If you have availabilità it's better to give these resources to your virtual machine.&lt;/P&gt;&lt;P&gt;If instead you haven't availability and you analyzed that you haven't an hard work for it, you could try with 8 CPUs and 8 GB RAM, monitoring it to understand if it reach to do its work.&lt;/P&gt;&lt;P&gt;The thing to analyze are: log parsing and eventual management of external syslog output queue.&lt;/P&gt;&lt;P&gt;In my experince, usually it's sufficient and I always start with these resources; only one time I had to give more resources because I saw that the HF was in trouble (slow queues) to do a very hard work: receive logs from some Universal Forwarders and syslogs from some appliances, parse them, manage an output syslog queue very large.&lt;/P&gt;&lt;P&gt;About hard disks, it's an intermediate Forwarder without local indexing, you can give 30 GB, or (better) 50.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 05:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549952#M91334</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-30T05:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware requirement for intermediate forwarder server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549971#M91337</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;&lt;P&gt;Thank for your helpful answer,&lt;/P&gt;&lt;P&gt;I have one more questions, please clear it for me:&lt;/P&gt;&lt;P&gt;1. Does only HF support intermediate forwarder ? how about Universal forwarder ?&lt;/P&gt;&lt;P&gt;2. When intermediate forwarder received logs like: Syslog from Firewall, IPS, Router.... and other log from universal forwarder. What will the intermediate forwarder do ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Storage the log and forward to Indexer, after that, deleted the logs ?&lt;/P&gt;&lt;P&gt;- Just forward the log, not storage logs ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks !&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 09:08:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549971#M91337</guid>
      <dc:creator>Thang_TV</dc:creator>
      <dc:date>2021-04-30T09:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware requirement for intermediate forwarder server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549973#M91339</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233999"&gt;@Thang_TV&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can use also an Universal Forwarder as Intermediate Forwarder, but I don't like it, I prefer HF.&lt;/P&gt;&lt;P&gt;Then remember always to use always at least two HFs as Intermediate to avoid Single Point of Failure.&lt;/P&gt;&lt;P&gt;Intermediate Forwarder usually doesn't locally index logs becaus in this way you pay twice license!&lt;/P&gt;&lt;P&gt;For this reason you don't need large storages on HFs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 09:19:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549973#M91339</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-30T09:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware requirement for intermediate forwarder server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549976#M91342</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank bro,&lt;/P&gt;&lt;P&gt;very helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 10:11:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549976#M91342</guid>
      <dc:creator>Thang_TV</dc:creator>
      <dc:date>2021-04-30T10:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Hardware requirement for intermediate forwarder server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549978#M91343</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233999"&gt;@Thang_TV&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see nect time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 10:13:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hardware-requirement-for-intermediate-forwarder-server/m-p/549978#M91343</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-30T10:13:11Z</dc:date>
    </item>
  </channel>
</rss>

