Minimum specifications for a production deployment
Splunk Enterprise Security has some minimum software and hardware requirements that you can increase according to your needs and usage. These specifications also apply to a single instance deployment of Splunk Enterprise Security.
The following table displays the minimum system and hardware requirements to install Splunk Enterprise Security:
Machine role | Minimum CPU | Minimum RAM | Minimum vCPU |
---|---|---|---|
Search head | 16 physical CPU cores | 32 GB | 32 vCPU |
Indexer | 16 physical CPU cores | 32 GB | 32 vCPU |
The minimum hardware specifications to run Splunk Enterprise Security for search head cluster peers is the same as those required by standalone deployments.
Splunk Enterprise Security stores some lookup files in a key-value store (KV Store).
See also
For more information about system requirements for KV Stores and other deployment considerations, see the product documentation:
- About the app key value store in the Splunk Enterprise Admin Manual
- Deployment considerations for Splunk Enterprise Security
Download Splunk Enterprise Security | Deployment considerations for Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 8.0.0, 8.0.1
Feedback submitted, thanks!