Deployment Architecture

What is the appropriate server sizing for Splunk Free on a Red Hat Linux instance running VMWare, 500MB log messaging per day?

ed_hickey
New Member

Running a POC with Splunk. Looking for the appropriate server sizing for a RH Linux instance running on VMWare. Max 500mb per day of log messaging.

Looking for CPU, Memory and Disk.

Thx Ed

Tags (3)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Sizing guides ands installation requirements -
http://docs.splunk.com/Documentation/Splunk/6.1.4/Installation/Systemrequirements http://docs.splunk.com/Documentation/Splunk/6.1.4/Installation/CapacityplanningforalargerSplunkdeplo...

Depending on data sources, but for 500mb/day POC, you can get away with minimal requirements. A 4vcore/4GB ram VM would probably be sufficient. Disk I/o is a contention point depending on what the use case is for your POC.

0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...