Splunk® Enterprise Security

Install and Upgrade Splunk Enterprise Security

Minimum specifications for a production deployment

Splunk Enterprise Security has some minimum software and hardware requirements that you can increase according to your needs and usage. These specifications also apply to a single instance deployment of Splunk Enterprise Security.

The following table displays the minimum system and hardware requirements to install Splunk Enterprise Security:

Machine role Minimum CPU Minimum RAM Minimum vCPU
Search head 16 physical CPU cores 32 GB 32 vCPU
Indexer 16 physical CPU cores 32 GB 32 vCPU


The minimum hardware specifications to run Splunk Enterprise Security for search head cluster peers is the same as those required by standalone deployments.

Splunk Enterprise Security stores some lookup files in a key-value store (KV Store).

See also

For more information about system requirements for KV Stores and other deployment considerations, see the product documentation:

Last modified on 08 August, 2024
Download Splunk Enterprise Security   Deployment considerations for Splunk Enterprise Security

This documentation applies to the following versions of Splunk® Enterprise Security: 8.0.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters