Getting Data In

Hard disk requirement for Splunk heavy forwarder

New Member

Can you please share the hard disk requirement
for Splunk enterprise and Splunk heavy forwarder

0 Karma

Esteemed Legend

What is your use case for HF? Probably you should be using UF. If you are using HF the correct way, then you will not need any special disk space requirements because nothing will be hitting disk and it all will be immediately forwarded to the Indexer Tier.

0 Karma

New Member

Hi, In splunk enterprise documentation, It is given like this we need 5 GB of Hard disk for Splunk Enterprise. In the same way ,I need hard disk space requirement for heavy forwarder. I am not able to find in documentation.

Platform Recommended hardware capacity/configuration
Non-Windows platforms 2x six-core, 2+ GHz CPU, 12GB RAM, Redundant Array of Independent Disks (RAID) 0 or 1+0, with a 64 bit OS installed.
Windows platforms 2x six-core, 2+ GHz CPU, 12GB RAM, RAID 0 or 1+0, with a 64-bit OS installed.
RAID 0 disk configurations do not provide fault-tolerance. Confirm that a RAID 0 configuration meets your data reliability needs before deploying a Splunk Enterprise indexer on a system configured with RAID 0.

Maintain a minimum of 5GB of free hard disk space on any Splunk Enterprise instance, including forwarders, in addition to the space required for any indexes. See Estimate your storage requirements in Capacity Planning for a procedure on how to estimate the space you need. Failure to maintain this level of free space can degrade performance and cause operating system failure and data loss.

0 Karma

Esteemed Legend

Hi Monica7,
if you're speaking of Storage, you have to do a Capacity Planning before define Hard Disks requirements (see Splunk Capacity Planning).
If instead you're speaking of Splunk system hard disks requirements you can see Splunk Hardware requirements.
I cannot access Docs to search paths.

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...