I want to mount an oversized indexer to be able to receive a minimum of 10GB of data per day.
As for the operating system, I had thought about Centos 7.
Do you have any other recommendation in particular? How much space would I need to leave for the operating system disk to install splunk?
Check out the sizing calculator at https://splunk-sizing.appspot.com/
You tagged the question as Splunk Enterprise Security, but it seems like it's not specific to that product. Perhaps you meant to use the "Splunk Enterprise" tag?