Skip to main content

Reference hardware

UXM is setup to handle 10.000+ Desktop agents and million of Web page requests per day.

The recommended architecture is to setup an Splunk Heavy-Forwarder with UXM (containing the NGINX/RabbitMQ queue) and send data via HTTP Event Collector (HEC) to the indexers.

 

 

Standalone environment

Recommended hardware for under 20.000 endpoints and 4 concurrent data analysis users.

Linux: https://mcgsystems.zendesk.com/hc/en-us/articles/360004118971-Install-on-Linux-Standalone-Splunk-Environment

ComponentNumber of serversCPUMemoryDiskSoftware
Data  Receiving, Analysis and Storage18 vCPU32 GB Ram300 GD SSD disk
Daily Splunk license usage: < 10 GBNGINXRabbitMQSplunk Search HeadSplunk Indexer

 

 

Small distributed environment

Recommended hardware for 20.000 endpoints and over 4 concurrent data analysis users.

Linux:https://mcgsystems.zendesk.com/hc/en-us/articles/360019062339-Install-on-Linux-Distributed-Splunk-Environment

ComponentNumber of serversCPUMemoryDiskSoftware
Data Collector1 per 20.000 endpoints8 vCPU12 GB Ram100 GD SSD diskSplunk Heavy ForwarderNGINXRabbitMQ
Data Analysis and Storage116 vCPU64 GB Ram100 GD SSD disk
500 GB disk for 1 year data retention
Daily Splunk license usage: 10 ~ 70 GBSplunk Search HeadSplunk Indexer

 

Large distributed environment

Recommended hardware for 70.000 latops/desktops/thin clients and 6000 Citrix servers with 60.000 Citrix users.

Linux: https://mcgsystems.zendesk.com/hc/en-us/articles/360019062339-Install-on-Linux-Distributed-Splunk-Environment

ComponentNumber of serversCPUMemoryDiskSoftware
Data Collector4 (1 per 20.000 endpoints)16 vCPU16 GB Ram300 GD SSD diskSplunk Heavy ForwarderNGINXRabbitMQ
Data Analysis148 vCPU62 GB Ram300 GD SSD diskSplunk Search Head
Data Storage148 vCPU62 GB Ram300 GD SSD disk
10 TB disk for 1 year data retention
Daily Splunk license usage: 75 GBSplunk Indexer