Deployment Architecture

Minimum requirement for splunk clustered environment



What is the Minimum requirement for splunk clustered environment?

How many searchheads/Indexers should be in place?

What is the CPU value?

Tags (1)
0 Karma


Hi @vijaysri,

this isn't a question for the Community, this is a question for a Splunk Architect or a Splunk Professional Service.

Anyway, you can find more infos at

About Indexers, you need at least two Indexers and a Master Node (usually dedicated), the number of Indexers depends on the volume of indexed logs, scheduled searches, users and the presence of Premium Apps as Enterprise Security or ITSI.

About Search Heads, you need at least three Search Heads and a Deployer (also shared with other roles), but the number of SHs depends on the user, scheduled searches and the presence of Premium Apps as Enterprise Security or ITSI.

About hardware reference, you can see at and they depends on the usual parameters.



Get Updates on the Splunk Community!

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...