Yeah, but running a stand-alone indexer/SH will be slow on a VM.. How much data do you plan on indexing per day? 500MB? What are the VM specs?
I'm assuming this will NOT be a production setup since it's Splunk Light?
I am not sure yet how much data we will be indexing. I am new to the environment so I am still trying to learn what is going on. It will be running on a production environment, but the environment is small. For Splunk Light to run properly what VM spec would you recommend we run it on, assuming a 500MB worth of data to index?
Why not use the Splunk Trial license which gives full features for 60 days? The Splunk Light version has limited features.
For Splunk Light or Splunk Trial, you can index up to a maximum of 500MB per day. Assuming this is a stand-alone machine you should have at a minimum of 12GB RAM and 16GB reserved vCPU.. Assuming you will only index 500MB per day, you can probably cut this in half