Deployment Architecture

Splunk Enterprise Installation Minimum Requirement

mohsplunking
Path Finder

Hello Splunkers,

I need some help to understand what will be the minimum spects required for Splunk Enterprise Installation for the purpose Heavy Forwarder where only it will receive logs from 1 source over Syslog and forward to Indexers.  Can I just use 2 CPU's 8 GB RAM and storage based of estimation of the log file sizes. I'm asking this because the official guide says it should be minimum 12 GB RAM , 4 Cores CPU.

Please if someone can advise on this.

Thanking you in advance,

 

Moh....

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk advises AGAINST sending syslog directly to a Splunk Instance.  The preferred practice is to send to a dedicated syslog server (rsyslog or syslog-ng) and forward to Splunk from there.  Alternatively, you can use Splunk Connect for Syslog (SC4S).

You can use any amount of resources you wish.  If there is a problem, however, Splunk Support may require you meet the recommended hardware specifications before they provide further support.

---
If this reply helps you, Karma would be appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust
As @richgalloway said don’t use splunk to terminate syslog feed. When you are using real syslog server then it’s better to use UF instead of HF to send those forward. Or use SC4S especially if you haven’t experience of running syslog server.
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...