Hi @jbanAtSplunk, this isn't a question for the Community but for a Splunk Architect. Anyway, there are many other parameters to answer to your question: is there an Indexer Cluster, if yes what...
See more...
Hi @jbanAtSplunk, this isn't a question for the Community but for a Splunk Architect. Anyway, there are many other parameters to answer to your question: is there an Indexer Cluster, if yes what's the Search Factor and The Replication Factor? is there a Search Head Cluster, are there Premium App as Enterprise Security or ITSI? how many concurrent users you foresee in the system? are there scheduled searches? Anyway, if you don't have ES or ITSI, you couls use around 3 Indexers. If you don't have a Search Head Cluster you can use one Search Head, if you have a Search Head Cluster you need at least three SHs and a Deployer, If you have an Indexer Cluster you need at least 3 Indexers and one Cluster Manager. If you have ES or ITSI the resources are completely different! For storage: if you don't have an Indexer Cluster you could consider: Storage = License*retention*0.5 = 500*30*0.5 = 7500 GB If you have an indexer Cluster the required storage depends on the above factors. About CPUs and RAMs: they depends on: presence of Premium App, number of concurrent users number of scheduled searches, so I cannot help you without these information, the only hint is to see at this url the reference hardware: https://docs.splunk.com/Documentation/Splunk/9.1.1/Capacity/Referencehardware Ciao. Giuseppe