Hi Laszlo,
we also had this problem.
First be aware that there is a big difference between an EP and an EC. The EC is just collection events and then forwarding them to an EP. The EP on the other side is storing the events and also searching them if the console is telling it to do so. So there is more workload on an EP, more active processes.
So you have different requirements for an EC than for an EP.
Some requirements I found are:
- you need 256GB of storage (I always take 300GB because the VM also needs to configure some swap and so on.)
- don't miss the IOPS even for a very small system your disk performance should not be less than 300 IOPS. (with less your system will probably react slow and freeze time by time.
Please see also this link:
https://www.ibm.com/support/knowledgecenter/en/SS42VS_7.3.2/com.ibm.qradar.doc/c_siem_vrt_ap_reqs.htmlMinimum RAM requirement is 12GB with 7.3.2 (but as it is a VM you can cut this after the installation ;-) , I would recommend at least 8GB for an EP and 4 GB for an EC (not tested!)
Minimum CPU requirement is 4 cores (I guess this is not so important, but as virtuell appliance how cares about cpu cores?)
I hope this helps.
Greetings Oliver
------------------------------
Kind regards
Oliver
------------------------------
Original Message:
Sent: Wed November 06, 2019 04:55 AM
From: Laszlo Pal
Subject: Absolut minimum HW config for EP
Hi,
I have a new client with a very small EPS (100). I'm going to use an EP to collect logs (surprisingly it can act as EC as well). I'm aware of the standard config of this appliance, but it is overkill for this, so what is the absolute minimum CPU and memory wise for an EP as a VM?
Thank you
Laszlo
------------------------------
Laszlo Pal
------------------------------