Getting Data In

What is the recommended hardware requirement for Heavy Forwarder that is indexing?

slebbie_splunk
Splunk Employee
Splunk Employee

What is the recommended hardware spec for a HF that is now indexing locally. Essentially, I know it's an Indexer that is just forwarding, so do we treat it as such in terms of hardware requirements?

12CPU? 12GB?

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

You can follow the reference architecture listed in docs. But what kind indexing volume is this box doing per day?

Without search load, 12gb + 12cores, and 900iops, should be able to deliver 200gb+ a day.

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

You can follow the reference architecture listed in docs. But what kind indexing volume is this box doing per day?

Without search load, 12gb + 12cores, and 900iops, should be able to deliver 200gb+ a day.

edoardo_vicendo
Builder

Hello,

Do you mean the 200GB/day is for an 12vCPU/12GB RAM/900 IOPS Heavy Forwarder that is indexing locally and also forwarding to Indexers but not performing local searches?

In this 200GB/day are you also including logs from internal indexes ( index=_* ) ?

If so, what about an Heavy Forwarder with same specs that is not locally indexing? How many GB/day can process (internal and non internal logs)?

Thanks a lot,

Edoardo

0 Karma

slebbie_splunk
Splunk Employee
Splunk Employee

To be honest, not much. 1.5gb. But there are massive blocked queues. Currently it's a 4 core box, more than likely a VM.

0 Karma

jet1276
Path Finder

I have seen Heavy Forwarder with 12 Core CPU and 12 GB RAM handling 500 GB/day logs.

But everything depends on how you configure the Splunk Deployment and Server configurations.

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...