Hello Yash,
I am going to try to shed some light on your question.
First of all, the recommended hardware requirement It will depend on the needs you have. For example, How many agents you will have monitoring, the number of events per second generated, if you will monitor other types of devices (network devices), how long you will need the data to be online, etc..
We kindly recommend at least the following:
- Resources for ElasticSearch, Logstash and Kibana node: 8 cores, 32 GB of RAM minimum and 64 GB max, 1 TB of disk space minimum. (However, this will depend on the data you store in Elastic)
- Resources for the Wazuh manager: 4 cores, 16 GB of RAM and 1TB disk space.
Depending on the number of agents in your environment, you could add more ElK nodes and managers to your architecture with these hardware requirements for scalability.
Hope this helps you. If you have any further questions, please do not hesitate to contact us.
Regards,
Miguel Casares