Deployment Architecture

Deployment Server Performance Reference

aojie654
Path Finder

Hi, Splunkers:

About a week ago, a customer asked me that is there a reference for deployment server which has 1200+ client?

They have the high speed LAN but not sure about CPU and Memory should configure to server.

Any idea for this?

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi aojie654,
in Splunk documentation, there isn't a clear requirement for Deployment Server infrastructure, they generally says that it's the same of other Splunk systems (at least 12 CPUs and 12 GB of RAM).
If you use the Monitoring Console Health Check, it says that at least you need 12 CPUs and 12 GB of RAM.
My hint is: usually Deployment Server is a Virtual System so start with a less configuration (e.g. 8 CPUs and 8 GB of RAM) and then monitor performances with the Monitoring Console and eventually improve configuration.

The only clear requirement is that, if you have more than 50 deployment clients, you have to use a dedicated server without any additional role!
If it's a physical server it's better but there's no problems with a virtual server.

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi aojie654,
in Splunk documentation, there isn't a clear requirement for Deployment Server infrastructure, they generally says that it's the same of other Splunk systems (at least 12 CPUs and 12 GB of RAM).
If you use the Monitoring Console Health Check, it says that at least you need 12 CPUs and 12 GB of RAM.
My hint is: usually Deployment Server is a Virtual System so start with a less configuration (e.g. 8 CPUs and 8 GB of RAM) and then monitor performances with the Monitoring Console and eventually improve configuration.

The only clear requirement is that, if you have more than 50 deployment clients, you have to use a dedicated server without any additional role!
If it's a physical server it's better but there's no problems with a virtual server.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...