The recommended size of CM is dependent of your environment. How many indexes, indexers, buckets etc. you have. As there are some task which don't use threads, as someone could expects, the most important requirement is performance of one core and also memory. Unfortunately there haven't been exact proposals from Splunk side, but you could get some hints from .conf presentations.