Getting Data In

Hard disk requirement for Splunk heavy forwarder

Monica7
New Member

Can you please share the hard disk requirement
for Splunk enterprise and Splunk heavy forwarder

0 Karma

woodcock
Esteemed Legend

What is your use case for HF? Probably you should be using UF. If you are using HF the correct way, then you will not need any special disk space requirements because nothing will be hitting disk and it all will be immediately forwarded to the Indexer Tier.

0 Karma

Monica7
New Member

Hi, In splunk enterprise documentation, It is given like this we need 5 GB of Hard disk for Splunk Enterprise. In the same way ,I need hard disk space requirement for heavy forwarder. I am not able to find in documentation.

Platform Recommended hardware capacity/configuration
Non-Windows platforms 2x six-core, 2+ GHz CPU, 12GB RAM, Redundant Array of Independent Disks (RAID) 0 or 1+0, with a 64 bit OS installed.
Windows platforms 2x six-core, 2+ GHz CPU, 12GB RAM, RAID 0 or 1+0, with a 64-bit OS installed.
RAID 0 disk configurations do not provide fault-tolerance. Confirm that a RAID 0 configuration meets your data reliability needs before deploying a Splunk Enterprise indexer on a system configured with RAID 0.

Maintain a minimum of 5GB of free hard disk space on any Splunk Enterprise instance, including forwarders, in addition to the space required for any indexes. See Estimate your storage requirements in Capacity Planning for a procedure on how to estimate the space you need. Failure to maintain this level of free space can degrade performance and cause operating system failure and data loss.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi Monica7,
if you're speaking of Storage, you have to do a Capacity Planning before define Hard Disks requirements (see Splunk Capacity Planning).
If instead you're speaking of Splunk system hard disks requirements you can see Splunk Hardware requirements.
I cannot access Docs to search paths.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...