What is the recommended hardware spec for a HF that is now indexing locally. Essentially, I know it's an Indexer that is just forwarding, so do we treat it as such in terms of hardware requirements?
You can follow the reference architecture listed in docs. But what kind indexing volume is this box doing per day?
Without search load, 12gb + 12cores, and 900iops, should be able to deliver 200gb+ a day.
View solution in original post
To be honest, not much. 1.5gb. But there are massive blocked queues. Currently it's a 4 core box, more than likely a VM.
I have seen Heavy Forwarder with 12 Core CPU and 12 GB RAM handling 500 GB/day logs.
But everything depends on how you configure the Splunk Deployment and Server configurations.