At my organization, we're planning to ingest about 100 GB/day, and leveraging 1 Heavy Forwarder to pull the following data sources, and sending those over to our index cluster:
Oracle Database Standard and Fine-Grained audit logs
Oracle WAF logs (via HTTP Event Collector which shall be configured on the HF)
Qualys Vulnerability Management Data
We are estimating that these data sources shall probably account for close to 30 GB/day in total, and are using Splunk ES in our environment.
Any recommendations on CPU and RAM specs? So far, we have a server where the HF shall be installed with 8 CPU and 32 GB RAM. Is that enough or should we scale down/up?