Getting Data In

Splunk Free deployment virtual machines

monkeydjohn
New Member

Hi,

Mrs,Mr

I want deploy the products Splunk Free on a virtual machines linux ( Centos7) or Windows ( 2012R2 or 2016)
Which are the prerequisite ?
I read a lot of document and many question but the preequisite relate to splunk entreprise .
The prerequisite are same in oder to splunk Entreprise and splunk Free?
So
• 12 vCPU
• 12 GB of RAM
• Minimum 1200 random seek operations per second disk performance (sustained)

Thanks

PS: I am French I hope which you understand my message and I am sorry in order to my fault spelling.

Tags (2)
0 Karma
1 Solution

jconger
Splunk Employee
Splunk Employee

The specifications depends on the amount of data ingested per day. The numbers referenced in the question are for an indexer that can ingest up to 300GB/day while supporting a search load.

https://docs.splunk.com/Documentation/Splunk/7.2.5/Capacity/Summaryofperformancerecommendations

The Splunk free license lets you index up to 500MB per day, so the hardware requirements are much less.

View solution in original post

0 Karma

jconger
Splunk Employee
Splunk Employee

The specifications depends on the amount of data ingested per day. The numbers referenced in the question are for an indexer that can ingest up to 300GB/day while supporting a search load.

https://docs.splunk.com/Documentation/Splunk/7.2.5/Capacity/Summaryofperformancerecommendations

The Splunk free license lets you index up to 500MB per day, so the hardware requirements are much less.

0 Karma

monkeydjohn
New Member

Hi jconger.

Thanks to reply me.

have you an idea of size vcpu , ram and storage in order to total users less than 4 if i use splunk free licence .
Just an idea .

0 Karma

jconger
Splunk Employee
Splunk Employee

CPU, RAM, and disk is based on data ingest and search rather than license type. At 500MB per day, you can run Splunk on a laptop computer or similar.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...