I've been using Splunk for less than a year and I'm trying to know how to size Splunk deployment(hardware requirement). I've read the Splunk Capacity Planning manual and the admin guides but would like to hear from people who have done it.
1800 clients in the environment
So How many indexers and forwarders should I have for this project? as I have 1800 clients and using 120GB a day.
Can one server do the job?
Also, I am not sure if I should use universal or Heavy forwarder. But it seems like Universal is the right one.
I'd appreciate any recommendations.
Thanks in advance,
... View more