Hi, We are planning to move our Splunk environment to our Nutanix infrastructure. We expect our collected logs to be 20-30 GB/Day and Splunk is mainly used as a SIEM solutions where around 4 users are accessing concurrently We had some internal discussions, and I wanted to understand if we can use less resources than the mentioned below to run Splunk+ES, and if any one is running a similar setup can share the used hardware specs Search head 24vCPU, 32GB ES search head 24vCPU, 32GB Indexer 24vCPU, 32GB License + Deployment 12vCPU, 16GB Thanks
... View more