Hello!
There's no one-size-fits-all formula for Wazuh deployment sizing since there are many variables you won't know until agents start sending data. Here's the iterative approach I'd recommend:
Start small and scale up: Begin with modest server capacity, then gradually feed in events while monitoring the system. Once you hit around 60% constant resource usage (CPU, RAM, network), increase resources incrementally based on your needs.
Initial setup recommendations depends on the required availability and resiliency, for example:
Capacity starting point for all nodes:
Add your data sources gradually over time rather than all at once. This gives you room to monitor performance and adjust capacity as needed. The nature of your events and collection mechanisms will determine whether you need to adjust the number of servers or their individual capacity to properly distribute the load.
After the process, servers might have more capacity than indexers. and usually the dashboard uses less resources than the rest.
Hope this helps with your planning!
Dear Gabriel ,
Apologies for the delayed response and thank you for your detailed explanation.
I understand your point; however, I’m still unclear about the storage estimation. In my case, the estimated event rate for my environment is approximately 20,000 EPS. I’ve outlined the detailed requirements below for your reference:
Requirements:
EPS: 20,000
Alert Retention (Hot): 90 days
Archive Log Retention (Cold): 365 days
Could you please assist me in calculating the required storage based on these parameters?
Or do I also need to allocate separate storage space for the Manager?
If I have to distribute this space in indexers, should I divide it by the number of indexer nodes?
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh | Mailing List" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/lP-OWauFH78/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/wazuh/d45d045e-7edd-4c08-881a-752ffb164fe3n%40googlegroups.com.