Splunk SOAR

Recommended Hardware Configuration for SOAR On-Prem with Unprivileged User Playbook Execution

Ramachandran
Explorer

Hi everyone! 👋
I’m currently working on a Splunk SOAR on-premises deployment and evaluating its performance using an AWS EC2 t3.xlarge instance (4 vCPU, 16 GB RAM, EBS-backed storage). I’d love your input on the following:
What would be a recommended build configuration (CPU, RAM, disc) to support this kind of usage in playbooks?
Does allowing multiple users to run playbooks simultaneously change the sizing recommendations?
Any experience with tuning playbook runners or autoscaling settings to handle user-driven playbook execution effectively?
Any advice or sizing tips from your deployments would be much appreciated.
Thanks in advance!

Labels (2)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @Ramachandran 

The recommended hardware specification for SOAR On-Premise is 

Processor1 server-class CPU, 4 to 8 cores
MemoryMinimum of 16GB RAM, 32GB recommended
StorageSplunk SOAR (On-premises) needs storage for multiple volumes:
  • Splunk SOAR (On-premises) home directory also known as <$PHANTOM_HOME>: 500GiB
    • mounted as either /opt/phantom/ or as <$PHANTOM_HOME>
  • Phantom data: 500GiB
    • mounted as either /opt/phantom/data or <$PHANTOM_HOME>/data
       
      The PostgreSQL database will be stored underneath the Phantom Data mount at: <$PHANTOM_HOME>/data/db
  • File share volumes: 500GiB
    • mounted as /opt/phantom/vault or <$PHANTOM_HOME>/vault

Disk space requirements vary depending on the volume of data ingested and the size of your production environment.

For more info check out https://help.splunk.com/en/splunk-soar/soar-on-premises/install-and-upgrade-soar-on-premises/6.4.1/s...

Note that 4vCPU doesnt necessarily = 1 Server Class CPU with 4 Cores as per the spec.

There are no specific requirements based on the number of playbooks but using the referenced hardware spec should cover full production use of SOAR and thus should handle your multiple playbook scenario.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Ramachandran 

The recommended hardware specification for SOAR On-Premise is 

Processor1 server-class CPU, 4 to 8 cores
MemoryMinimum of 16GB RAM, 32GB recommended
StorageSplunk SOAR (On-premises) needs storage for multiple volumes:
  • Splunk SOAR (On-premises) home directory also known as <$PHANTOM_HOME>: 500GiB
    • mounted as either /opt/phantom/ or as <$PHANTOM_HOME>
  • Phantom data: 500GiB
    • mounted as either /opt/phantom/data or <$PHANTOM_HOME>/data
       
      The PostgreSQL database will be stored underneath the Phantom Data mount at: <$PHANTOM_HOME>/data/db
  • File share volumes: 500GiB
    • mounted as /opt/phantom/vault or <$PHANTOM_HOME>/vault

Disk space requirements vary depending on the volume of data ingested and the size of your production environment.

For more info check out https://help.splunk.com/en/splunk-soar/soar-on-premises/install-and-upgrade-soar-on-premises/6.4.1/s...

Note that 4vCPU doesnt necessarily = 1 Server Class CPU with 4 Cores as per the spec.

There are no specific requirements based on the number of playbooks but using the referenced hardware spec should cover full production use of SOAR and thus should handle your multiple playbook scenario.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...