Deployment Architecture

Splunk Enterprise Installation Minimum Requirement

mohsplunking
Path Finder

Hello Splunkers,

I need some help to understand what will be the minimum spects required for Splunk Enterprise Installation for the purpose Heavy Forwarder where only it will receive logs from 1 source over Syslog and forward to Indexers.  Can I just use 2 CPU's 8 GB RAM and storage based of estimation of the log file sizes. I'm asking this because the official guide says it should be minimum 12 GB RAM , 4 Cores CPU.

Please if someone can advise on this.

Thanking you in advance,

 

Moh....

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk advises AGAINST sending syslog directly to a Splunk Instance.  The preferred practice is to send to a dedicated syslog server (rsyslog or syslog-ng) and forward to Splunk from there.  Alternatively, you can use Splunk Connect for Syslog (SC4S).

You can use any amount of resources you wish.  If there is a problem, however, Splunk Support may require you meet the recommended hardware specifications before they provide further support.

---
If this reply helps you, Karma would be appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust
As @richgalloway said don’t use splunk to terminate syslog feed. When you are using real syslog server then it’s better to use UF instead of HF to send those forward. Or use SC4S especially if you haven’t experience of running syslog server.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...