Installation

Is there any information on Heavy Forwarder minimum specifications?

adnankhan5133
Communicator

At my organization, we're planning to ingest about 100 GB/day, and leveraging 1 Heavy Forwarder to pull the following data sources, and sending those over to our index cluster:

  • Oracle Database Standard and Fine-Grained audit logs

  • Oracle WAF logs (via HTTP Event Collector which shall be configured on the HF)

  • Qualys Vulnerability Management Data

We are estimating that these data sources shall probably account for close to 30 GB/day in total, and are using Splunk ES in our environment.

Any recommendations on CPU and RAM specs? So far, we have a server where the HF shall be installed with 8 CPU and 32 GB RAM. Is that enough or should we scale down/up?

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
That should be enough.
However, it's below Splunk minimum recommendations and if there is a problem Splunk will ask you to bring the server up to spec.
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust
That should be enough.
However, it's below Splunk minimum recommendations and if there is a problem Splunk will ask you to bring the server up to spec.
---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...